Vulnerability CVE-2016-0321


Published: 2016-07-17   Modified: 2016-07-18

Description:
IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows local users to discover passwords by leveraging access to the victim account and executing a PowerShell script.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
IBM -> Personal communications 

 References:
http://www-01.ibm.com/support/docview.wss?uid=swg1IT12006
http://www-01.ibm.com/support/docview.wss?uid=swg21981692

Copyright 2024, cxsecurity.com

 

Back to Top