PT-2011-4069 · Ibm · Ibm Tivoli Directory Server

Published

2011-07-17

·

Updated

2017-08-29

·

CVE-2011-2759

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Directory Server versions prior to 6.2.0.3-TIV-ITDS-IF0004
Description The issue concerns the login page of IDSWebApp in the Web Administration Tool, where the lack of an autocomplete attribute for authentication fields makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Recommendations For versions prior to 6.2.0.3-TIV-ITDS-IF0004, update to version 6.2.0.3-TIV-ITDS-IF0004 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2759

Affected Products

Ibm Tivoli Directory Server