PT-2011-3390 · Ibm · Ibm Tivoli Directory Server

Publicado

2011-04-21

·

Atualizado

2017-08-17

·

CVE-2011-1820

CVSS v2.0

1.7

Baixa

VetorAV:L/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Directory Server versions 5.2 through 5.2.0.5-TIV-ITDS-IF0010 IBM Tivoli Directory Server versions 6.0 through 6.0.0.67 IBM Tivoli Directory Server versions 6.1 through 6.1.0.40 IBM Tivoli Directory Server versions 6.2 through 6.2.0.16 IBM Tivoli Directory Server versions 6.3 through 6.3.0.3
Description The issue is related to the improper handling of the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations. This might allow attackers to obtain sensitive information by reading the audit log.
Recommendations For version 5.2, update to 5.2.0.5-TIV-ITDS-IF0010 or later. For version 6.0, update to 6.0.0.67 or later. For version 6.1, update to 6.1.0.40 or later. For version 6.2, update to 6.2.0.16 or later. For version 6.3, update to 6.3.0.3 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1820

Produtos afetados

Ibm Tivoli Directory Server