Executive brief
IBM Tivoli Netcool Impact, a software suite used for automating IT operations and event management, is affected by a vulnerability where sensitive information is recorded in plain text within system log files. A local user with access to the system could read these logs to obtain confidential data, potentially leading to unauthorized access or further compromise of the environment. Organizations should upgrade to the latest fix pack to ensure sensitive data is properly protected.
Technical details
IBM Tivoli Netcool Impact (versions 7.1.0.0 through 7.1.0.37) is vulnerable to information disclosure due to the insertion of sensitive information into log files (CWE-532). The vulnerability allows a local attacker with access to the file system to read sensitive data that has been improperly recorded in the application logs. While the attack vector is local, IBM has assigned a high severity score (8.4) suggesting the data exposed could facilitate significant unauthorized actions. The issue is resolved in IBM Tivoli Netcool Impact 7.1.0 Fix Pack 38 (7.1.0.38).
Affected products
- IBM Tivoli Netcool Impact 7.1.0.0 - 7.1.0.37
Timeline
- 2026-04-01: advisory: Initial publication by IBM
- 2026-04-08: disclosed: NVD publication date