CVE-2021-38901
Description
IBM Spectrum Protect Operations Center 7.1, under special configurations, could allow a local user to obtain highly sensitive information. IBM X-Force ID: 209610.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Spectrum Protect Operations Center 7.1 may log user credentials in plaintext when tracing is enabled, exposing highly sensitive information to local users.
Vulnerability
CVE-2021-38901 affects IBM Spectrum Protect Operations Center version 7.1.0.000 through 7.1.13.xxx [1]. Under special configurations, specifically when tracing is enabled, user credentials may be displayed in the trace file in plain text [1]. This does not affect the software in its default configuration.
Exploitation
An attacker must have local access to the file system where trace files are stored [1]. The attacker does not require authentication to the Operations Center itself, but needs the ability to read local files on the host. Exploitation is only possible if tracing has been previously enabled by an administrator, and the trace files have not been deleted [1]. The attack complexity is high because the attacker must locate and access the trace file among possibly many system files.
Impact
Successful exploitation leads to the disclosure of highly sensitive information, specifically user credentials in plain text [1]. This results in a confidentiality breach with a CVSS base score of 5.1 (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) [1]. The impact is limited to confidentiality; integrity and availability are not affected.
Mitigation
IBM has not released a software fix for this issue [1]. The recommended mitigation is to not enable tracing unless explicitly instructed to do so by IBM, and to delete any existing trace files that are no longer needed [1]. Organizations should restrict local file system access to trusted administrators only.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =7.1
- IBM/Spectrum Protect Operations Centerv5Range: 7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/209610mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6524924mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.