(IBM Issues Fix for IBM Cognos Command Center) IBM Java Flaw Lets Local Users Obtain Sensitive Kerberos Credentials Information on the Target System
|
SecurityTracker Alert ID: 1034607 |
SecurityTracker URL: http://securitytracker.com/id/1034607
|
CVE Reference:
CVE-2015-5006
(Links to External Site)
|
Date: Jan 7 2016
|
Impact:
Disclosure of authentication information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): Command Center 10.1, 10.2, 10.2.1, 10.2.2, 10.2.3
|
Description:
A vulnerability was reported in IBM Java. A physically local user can obtain sensitive information from the Kerberos Credential Cache. IBM Cognos Command Center is affected.
No details were provided.
|
Impact:
A physically local user can obtain sensitive information from the Kerberos Credential Cache.
|
Solution:
IBM has issued a fix for IBM Cognos Command Center.
The IBM advisory is available at:
https://www-304.ibm.com/support/docview.wss?uid=swg21972446
|
Vendor URL: www-304.ibm.com/support/docview.wss?uid=swg21972446 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: Windows (2003)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|