5.5
CVE-2016-5967
- EPSS 0.05%
- Veröffentlicht 25.11.2016 03:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Rational Asset Analyzer Version6.1.0
Ibm ≫ Rational Asset Analyzer Version6.1.0.1
Ibm ≫ Rational Asset Analyzer Version6.1.0.2
Ibm ≫ Rational Asset Analyzer Version6.1.0.3
Ibm ≫ Rational Asset Analyzer Version6.1.0.4
Ibm ≫ Rational Asset Analyzer Version6.1.0.5
Ibm ≫ Rational Asset Analyzer Version6.1.0.6
Ibm ≫ Rational Asset Analyzer Version6.1.0.7
Ibm ≫ Rational Asset Analyzer Version6.1.0.8
Ibm ≫ Rational Asset Analyzer Version6.1.0.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.129 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.