PT-2014-3079 · Ibm · Ibm Platform Symphony
Publicado
2014-01-21
·
Atualizado
2017-08-29
·
CVE-2013-6305
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Platform Symphony versions 5.2 before build 229037
IBM Platform Symphony versions 6.1.0.1 before build 229073
Description
The issue allows context-dependent attackers to obtain sensitive information by leveraging knowledge of the credentials encryption key used across different customers' installations.
Recommendations
For IBM Platform Symphony version 5.2 before build 229037, update to a version that uses unique credentials encryption keys for each customer's installation.
For IBM Platform Symphony version 6.1.0.1 before build 229073, update to a version that uses unique credentials encryption keys for each customer's installation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Platform Symphony