IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.
References
Configurations
History
21 Nov 2024, 01:35
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1OA38586 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/74641 - |
Information
Published : 2012-04-09 20:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-0742
Mitre link : CVE-2012-0742
CVE.ORG link : CVE-2012-0742
JSON object : View
Products Affected
ibm
- tivoli_event_pump
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor