Skip to main content

Cryptographic Issues


Severity Medium
Score 5/10


IBM Maximo Asset Management 7.1 through, 7.5.0 before IFIX002, and 7.6.0 before IFIX001; Maximo Asset Management 7.5.x before IFIX002 and 7.6.0 before IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.

  • LOW
  • NONE
  • NONE
  • NONE

CWE-310 - Cryptographic Issues

Cryptographic issues is a category of weaknesses related to the design and implementation of the confidentiality and integrity of data. If not addressed, the weaknesses in this category can lead to data quality degradation.


Advisory Timeline

  • Published