Vulnerability Description
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Endpoint Manager For Remote Control | 9.0.0 |
| Ibm | Tivoli Remote Control | 5.1.2 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88309VDB EntryVendor Advisory
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwoVendor Advisory
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwoVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88309VDB EntryVendor Advisory
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwoVendor Advisory
- https://www.ibm.com/blogs/psirt/ibm-security-bulletin-insecure-storage-of-passwoVendor Advisory
FAQ
What is CVE-2013-5461?
CVE-2013-5461 is a vulnerability with a CVSS score of 8.8 (HIGH). IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by l...
How severe is CVE-2013-5461?
CVE-2013-5461 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5461?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Endpoint Manager For Remote Control, Ibm Tivoli Remote Control.