Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34gw-343r-pm56

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

EPSS

Процентиль: 16%
0.0005
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 14 лет назад

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

EPSS

Процентиль: 16%
0.0005
Низкий

Дефекты

CWE-200