Vulnerability Name: | CVE-2013-0534 (CCN-82656) | ||||||||
Assigned: | 2012-12-16 | ||||||||
Published: | 2013-06-12 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory. | ||||||||
CVSS v3 Severity: | 2.9 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
1.0 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-0534 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21635218 Source: CCN Type: IBM Security Bulletin 1636154 IBM Notes may fail to zero the plaintext password within memory (CVE-2013-0534) Source: CCN Type: BID-60536 IBM Sametime CVE-2013-0534 Local Information Disclosure Vulnerability Source: XF Type: UNKNOWN notes-cve20130534-info-disclosure(82656) Source: XF Type: UNKNOWN notes-cve20130534-info-disclosure(82656) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |