VulnerabilityModified
CVE-2016-5967
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
MEDIUM 5.5EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM native logs.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.32% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- ibm/rational asset analyzer
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI61540Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21990215Vendor Advisory
- http://www.securityfocus.com/bid/93145
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI61540Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21990215Vendor Advisory
- http://www.securityfocus.com/bid/93145
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.