IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7091942 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/268265 | vdb entry |