CVE-2014-8923: IBM Security Identity Manager Active Directory Adapter
Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.
Affected products
- IBM Security Identity Manager Active Directory Adapter: up to and including 6.0.14
- IBM Tivoli Identity Manager Active Directory Adapter: up to and including 5.1.20
Published 2015-03-25. Last modified 2026-06-17.