IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21997983 | patch vendor advisory |
http://www.securitytracker.com/id/1037764 | vdb entry |
http://www.securityfocus.com/bid/95905 | third party advisory vdb entry |