CVE-2013-5461

IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:endpoint_manager_for_remote_control:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:endpoint_manager_for_remote_control:9.0.1:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:ibm:tivoli_remote_control:5.1.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:57

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/88309 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/88309 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-ibm-endpoint-manager-for-remote-control-cve-2013-5461/ - Vendor Advisory () https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-ibm-endpoint-manager-for-remote-control-cve-2013-5461/ - Vendor Advisory
References () https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-tivoli-remote-control-cve-2013-5461/ - Vendor Advisory () https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-tivoli-remote-control-cve-2013-5461/ - Vendor Advisory

Information

Published : 2018-04-27 16:29

Updated : 2024-11-21 01:57


NVD link : CVE-2013-5461

Mitre link : CVE-2013-5461

CVE.ORG link : CVE-2013-5461


JSON object : View

Products Affected

ibm

  • endpoint_manager_for_remote_control
  • tivoli_remote_control
CWE
CWE-255

Credentials Management Errors