Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IBM WebSphere ikeyman Weak Encrypted Password Vulnerability

IBM WebSphere ships with a tool called 'ikeyman' that encrypts server certificates/key pairs when the IBM HTTP Server and SSL connections are enabled. Ikeyman stores the password in a stash file which can be easily decrypted through the use of a freely available script (see Exploit tab).







 

Privacy Statement
Copyright 2009, SecurityFocus