Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x78w-w3vx-6qmj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.

EPSS

Процентиль: 56%
0.00342
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 14 лет назад

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.

EPSS

Процентиль: 56%
0.00342
Низкий

Дефекты

CWE-287