|
IBM WebSphere ikeyman Weak Encrypted Password Vulnerability
IBM WebSphere ships with a tool called 'ikeyman' that encrypts server certificates/key pairs when the IBM HTTP Server and SSL connections are enabled. Ikeyman stores the password in a stash file which can be easily decrypted through the use of a freely available script (see Exploit tab). |
|
|
Privacy Statement |