Vulnerability Name: | CVE-2013-4040 (CCN-86176) | ||||||||||||
Assigned: | 2013-06-07 | ||||||||||||
Published: | 2014-05-07 | ||||||||||||
Updated: | 2018-06-13 | ||||||||||||
Summary: | IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive information by reading the files. IBM X-Force ID: 86176. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-275 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-4040 Source: CCN Type: IBM Security Bulletin 1672253 Security improvement: More restricted permission on TADDM files on UNIX-like servers Source: XF Type: UNKNOWN ibm-tivoli-cve20134040-info-disc(86176) Source: XF Type: VDB Entry, Vendor Advisory ibm-tivoli-cve20134040-info-disc(86176) Source: CONFIRM Type: Mitigation, Patch, Vendor Advisory https://www-01.ibm.com/support/docview.wss?uid=swg21672253 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |