#VU67187 Cleartext storage of sensitive information in IBM Security Risk Manager


Published: 2022-09-12

Vulnerability identifier: #VU67187

Vulnerability risk: Low

CVSSv3.1: 4.3 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-38911

CWE-ID: CWE-312

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
IBM Security Risk Manager
Other software / Other software solutions

Vendor: IBM Corporation

Description

The vulnerability allows an authenticated privileged user to gain access to sensitive information.

The vulnerability exists due to IBM Security Risk Manager stores user credentials in plain clear text. An authenticated privileged user can trigger the vulnerability and gain access to sensitive information.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

IBM Security Risk Manager: 1.7.0.0


External links
http://exchange.xforce.ibmcloud.com/vulnerabilities/209940
http://www.ibm.com/support/pages/node/6505281


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability