PT-2014-3079 · Ibm · Ibm Platform Symphony
Published
2014-01-21
·
Updated
2017-08-29
·
CVE-2013-6305
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Platform Symphony versions 5.2 before build 229037
IBM Platform Symphony versions 6.1.0.1 before build 229073
Description
The issue allows context-dependent attackers to obtain sensitive information by leveraging knowledge of the credentials encryption key used across different customers' installations.
Recommendations
For IBM Platform Symphony version 5.2 before build 229037, update to a version that uses unique credentials encryption keys for each customer's installation.
For IBM Platform Symphony version 6.1.0.1 before build 229073, update to a version that uses unique credentials encryption keys for each customer's installation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Platform Symphony