CVE-2012-0742

low
Published 2012-04-09 · Modified 2026-04-29
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1OA38586

Application impact

VendorProductVersionsFixed
ibm ibmtivoli_event_pump4.2.2

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.