CVE-2026-4788

8.4

IBM · Tivoli Netcool Impact

IBM Tivoli Netcool Impact versions 7.1.0.0 through 7.1.0.37 are susceptible to the exposure of sensitive information stored within system log files that can be accessed by a local user.

Executive summary

A vulnerability in IBM Tivoli Netcool Impact allows local users to access sensitive information through insecure log file storage, posing a significant risk to system confidentiality and integrity.

Vulnerability

This is an insertion of sensitive information into log files (CWE-532) that allows a local, unauthenticated user to read potentially sensitive data that should be protected.

Business impact

The exposure of sensitive information in log files can lead to the compromise of credentials, configuration secrets, or other proprietary data, potentially facilitating further unauthorized access. Given the CVSS score of 8.4, this vulnerability represents a high risk to business operations, as it could lead to full system compromise if sensitive administrative tokens or keys are leaked.

Remediation

Immediate Action: Upgrade to IBM Tivoli Netcool Impact 7.1.0 Fix Pack 38 or later to ensure sensitive information is no longer written to accessible log files.

Proactive Monitoring: Audit local file access permissions and monitor system logs for signs of unauthorized access or suspicious enumeration attempts by local users.

Compensating Controls: Restrict local system access to authorized personnel only and apply strict file system permissions to log directories to prevent non-privileged users from reading log contents.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The high severity of this vulnerability necessitates immediate attention to prevent local privilege escalation or information theft. System administrators should prioritize applying the provided Fix Pack 38 to all affected instances of Tivoli Netcool Impact to remediate the insecure logging behavior.

More IBM CVEs

Sources