PT-2014-3079 · Ibm · Ibm Platform Symphony

Publicado

2014-01-21

·

Atualizado

2017-08-29

·

CVE-2013-6305

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Platform Symphony versions 5.2 before build 229037 IBM Platform Symphony versions 6.1.0.1 before build 229073
Description The issue allows context-dependent attackers to obtain sensitive information by leveraging knowledge of the credentials encryption key used across different customers' installations.
Recommendations For IBM Platform Symphony version 5.2 before build 229037, update to a version that uses unique credentials encryption keys for each customer's installation. For IBM Platform Symphony version 6.1.0.1 before build 229073, update to a version that uses unique credentials encryption keys for each customer's installation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6305

Produtos afetados

Ibm Platform Symphony