PT-2013-1723 · Ibm · Ibm Infosphere Information Server+1

Publicado

2013-01-31

·

Atualizado

2017-08-29

·

CVE-2012-4832

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Information Services Framework (ISF) in IBM InfoSphere Information Server versions 8.1 through 8.5 before FP3, 8.7 Information Services Framework (ISF) in IBM InfoSphere Business Glossary versions 8.1.1 through 8.1.2
Description The issue makes it easier for remote attackers to obtain access by leveraging an unattended workstation, as the login page does not have an off autocomplete attribute for the password field.
Recommendations For IBM InfoSphere Information Server versions 8.1 through 8.5 before FP3, 8.7, consider disabling the login page's autocomplete feature for the password field until a patch is available. For IBM InfoSphere Business Glossary versions 8.1.1 through 8.1.2, consider disabling the login page's autocomplete feature for the password field until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4832

Produtos afetados

Ibm Infosphere Business Glossary
Ibm Infosphere Information Server