IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
References
Configurations
History
21 Nov 2024, 01:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/88309 - VDB Entry, Vendor Advisory | |
References | () https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-ibm-endpoint-manager-for-remote-control-cve-2013-5461/ - Vendor Advisory | |
References | () https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwords-in-tivoli-remote-control-cve-2013-5461/ - Vendor Advisory |
Information
Published : 2018-04-27 16:29
Updated : 2024-11-21 01:57
NVD link : CVE-2013-5461
Mitre link : CVE-2013-5461
CVE.ORG link : CVE-2013-5461
JSON object : View
Products Affected
ibm
- endpoint_manager_for_remote_control
- tivoli_remote_control
CWE
CWE-255
Credentials Management Errors