PT-2020-10965 · Ibm · Ibm Security Directory Server
Published
2020-02-04
·
Updated
2020-02-04
·
CVE-2019-4551
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Directory Server version 6.4.0
Description
The issue allows anonymous users access to protected areas due to a lack of authentication check for a critical resource or functionality.
Recommendations
For IBM Security Directory Server version 6.4.0, consider restricting access to protected areas until a proper authentication mechanism is implemented. As a temporary workaround, review and enforce access controls to minimize the risk of unauthorized access.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Directory Server