IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 166627.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_key_lifecycle_manager | Ibm | 3.0 (including) | 3.0.0.2 (including) |
Security_key_lifecycle_manager | Ibm | 3.0.1 (including) | 3.0.1.1 (including) |