CVE-2019-4676: High severity ibm security identity manager virtual appliance vulnerability
IBM Security Identity Manager stores user credentials in plain in clear text which can be read by a local user.
Other sources
IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171512.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4676?
The severity of CVE-2019-4676 is high, with a CVSS score of 7.8.
How does CVE-2019-4676 impact IBM Security Identity Manager Virtual Appliance 7.0.2?
CVE-2019-4676 allows a local user to read user credentials stored in plain text in IBM Security Identity Manager Virtual Appliance 7.0.2.
Is there a fix for CVE-2019-4676?
Yes, there is a patch available for IBM Security Identity Manager Virtual Appliance 7.0.2. You can download it from IBM's Fix Central.
How can I download the patch for CVE-2019-4676?
You can download the patch for CVE-2019-4676 from IBM's Fix Central website using the provided URL.
Is IBM Security Identity Manager Virtual Appliance 7.0.1 affected by CVE-2019-4676?
Yes, IBM Security Identity Manager Virtual Appliance 7.0.1 is also affected by CVE-2019-4676. A patch is available for this version as well.