Vulnerability Name: | CCN-60740 | ||||||
Published: | 2010-07-26 | ||||||
Updated: | 2010-07-26 | ||||||
Summary: | IBM Tivoli Directory Server could allow a local attacker to obtain sensitive information, caused by the storing of the DB2 admin password in cleartext within the ldapinst.log file. An attacker could exploit this vulnerability to gain unauthorized access to the system to obtain sensitive information. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: SA40734 IBM Tivoli Directory Server DB2 Password Information Disclosure Source: CCN Type: IBM APAR IO12776 DB2 password appears twice in ldapinst.log Source: CCN Type: IBM Support and Downloads IBM Tivoli Directory Server, Version 6.1.0.4-TIV-ITDS-IF0006 Source: CCN Type: OSVDB ID: 66650 IBM Tivoli Directory Server ldapinst.log DB2 Admin Cleartext Password Storage Source: CCN Type: BID-42015 IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability Source: XF Type: UNKNOWN ibm-tds-db2-info-disclosure(60740) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |