Vulnerability Bulletins

IBM Security Bulletin: IBM Personal Communications could allow a remote user to obtain sensitive information including user passwords, allowing unauthorized access. (CVE-2016-0321)

   
Affected software IBM
 
IBM Personal Communications is susceptible to unauthorized access vulnerability when running on a compromised system (by the victim opening a mail with a malicious attachment or visiting a malicious website). Malware could run with user privileges but not necessarily having access to the password. An attacker could retrieve user credentials by running PowerShell Script and by exploiting design flaw in IBM Personal Communications to extract users’ password.CVE(s): CVE-2016-0321Affected

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-personal-communications-could-allow-a-remote-user-to-obtain-sensitive-information-including-user-passwords-allowing-unauthorized-access-cve-2016-0321/