漏洞标题
IBM Security Verify Bridge 信息泄露漏洞
漏洞描述信息
IBM Security Verify Bridge Directory Sync 1.0.1 至 1.0.12、IBM Security Verify Gateway for Windows Login 1.0.1 至 1.0.10 以及 IBM Security Verify Gateway for Radius 1.0.1 至 1.0.11 在配置文件中存储用户凭据,这些凭据可被本地用户读取。
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
不充分的凭证保护机制
漏洞标题
IBM Security Verify Bridge information disclosure
漏洞描述信息
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
配置文件中存储口令