CVE-2015-5013
MEDIUMIBM Security Access Manager For Web 8... - Insufficiently Protected Credentials
Title source: ruleDescription
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
Scores
CVSS v3
5.5
EPSS
0.0006
EPSS Percentile
19.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
draft
Affected Products (3)
ibm/security_access_manager_for_web_8.0_firmware
ibm/security_access_manager_for_mobile
ibm/security_access_manager_9.0_firmware
Timeline
Published
Feb 08, 2017
Tracked Since
Feb 18, 2026