Vulnerabilities > CVE-2012-3310 - Credentials Management vulnerability in IBM Tivoli Federated Identity Manager
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://www.ibm.com/support/docview.wss?uid=swg21615977
- http://www.ibm.com/support/docview.wss?uid=swg21615977
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26822
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26822
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26823
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26823
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26824
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV26824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77695
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77695