PT-2020-10962 · Ibm · Ibm Security Directory Server
Published
2020-10-29
·
Updated
2020-10-30
·
CVE-2019-4547
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Directory Server version 6.4.0
Description
The issue generates an error message that includes sensitive information about its environment, users, or associated data.
Recommendations
For IBM Security Directory Server version 6.4.0, consider implementing error message filtering to prevent the disclosure of sensitive information. As a temporary workaround, restrict access to error messages to minimize the risk of information leakage. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Directory Server