PT-2018-4090 · Ibm+1 · Ibm Tivoli Application Dependency Discovery Manager+1

Published

2018-05-24

·

Updated

2018-06-28

·

CVE-2013-3023

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Application Dependency Discovery Manager (TADDM) versions 7.1.2 and 7.2.0 through 7.2.1.4
Description The issue allows remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used.
Recommendations For versions 7.1.2, consider restricting access to sensitive information to minimize the risk of exploitation. For versions 7.2.0 through 7.2.1.4, consider using a secure protocol instead of HTTP to protect the session. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3023

Affected Products

Ibm Tivoli Application Dependency Discovery Manager
Apache Tomcat