10
CVSSv2

CVE-1999-0944

Published: 24/10/1999 Updated: 17/08/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.

Exploits

source: wwwsecurityfocuscom/bid/1763/info IBM WebSphere ships with a tool called 'ikeyman' that encrypts server certificates/key pairs when the IBM HTTP Server and SSL connections are enabled Ikeyman stores the password in a stash file which can be easily decrypted through the use of a freely available script #!/usr/bin/perl -w # # uns ...