CVE-2016-5967

MEDIUM

IBM Rational Asset Analyzer <6.1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21990215
Broken Link vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI61540
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93145

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (10)
ibm/rational_asset_analyzer 6.1.0
ibm/rational_asset_analyzer 6.1.0.1
ibm/rational_asset_analyzer 6.1.0.2
ibm/rational_asset_analyzer 6.1.0.3
ibm/rational_asset_analyzer 6.1.0.4
ibm/rational_asset_analyzer 6.1.0.5
ibm/rational_asset_analyzer 6.1.0.6
ibm/rational_asset_analyzer 6.1.0.7
ibm/rational_asset_analyzer 6.1.0.8
ibm/rational_asset_analyzer 6.1.0.9
Published Nov 25, 2016
Tracked Since Feb 18, 2026