Vulnerability Bulletins

IBM Security Bulletin: IBM Capacity Management Analytics could allow a localuser on the CMA install machine to obtain other CMA users encrypted usernames and passwords (CVE-2105-7434)

   
Affected software IBM
 
The encrypted password in setenv.sh is always the same which becomes easy to decrypt CVE(s): CVE-2015-7434Affected product(s) and affected version(s):IBM Capacity Management Analytics 2.1.0.0 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21974559X-Force Database: http://exchange.xforce.ibmcloud.com/vulnerabilities/107863

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_capacity_management_analytics_could_allow_a_localuser_on_the_cma_install_machine_to_obtain_other_cma_user_s_encrypted_usernames_and_passwords_cve_2105_7434?lang=en_us