{"api_version":"1","generated_at":"2026-07-23T08:51:46+00:00","cve":"CVE-2013-0599","urls":{"html":"https://cve.report/CVE-2013-0599","api":"https://cve.report/api/cve/CVE-2013-0599.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-0599","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-0599"},"summary":{"title":"CVE-2013-0599","description":"IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.","state":"PUBLISHED","assigner":"ibm","published_at":"2013-05-28 16:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83613","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83613","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21637151","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21637151","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Security Bulletin: Vulnerability in Rational Directory Server help files system with potential for  debug info in error message (CVE-2013-0599) - United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/60107","name":"http://www.securityfocus.com/bid/60107","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-0599","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0599","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"5.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"5.1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"5.2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"5.2.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"5.1.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"599","vulnerable":"1","versionEndIncluding":"5.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"rational_directory_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T14:33:05.268Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"60107","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/60107"},{"name":"ibm-iehs-cve20130599-info-disclosure(83613)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83613"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21637151"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-05-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"60107","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/60107"},{"name":"ibm-iehs-cve20130599-info-disclosure(83613)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83613"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21637151"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2013-0599","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"60107","refsource":"BID","url":"http://www.securityfocus.com/bid/60107"},{"name":"ibm-iehs-cve20130599-info-disclosure(83613)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83613"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21637151","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21637151"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2013-0599","datePublished":"2013-05-28T16:00:00.000Z","dateReserved":"2012-12-16T00:00:00.000Z","dateUpdated":"2024-08-06T14:33:05.268Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-05-28 16:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:*:*:*:*:*:*:*:*","versionEndIncluding":"5.1.1.2","matchCriteriaId":"77ABEE3A-DD6B-41BE-846E-5091542A2678"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:5.1.1:*:*:*:*:*:*:*","matchCriteriaId":"863115B5-B43A-4926-957F-3D0518CB8E62"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:5.1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"993B628A-3C52-461A-A507-A40BE4C823DA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:*:*:*:*:*:*:*:*","versionEndIncluding":"5.2.1","matchCriteriaId":"8651CF37-495D-4CFD-BEA0-21400E549680"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:5.2:*:*:*:*:*:*:*","matchCriteriaId":"3279036F-BE1A-44FD-AF4C-9C61A1F165D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:5.2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"BE5852C2-A255-427B-A27F-ED792DA8FB9E"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:rational_directory_server:5.2.0.2:*:*:*:*:*:*:*","matchCriteriaId":"950DD182-C8EE-45B8-A32E-213CFC26DCEC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"599","Ordinal":"1","Title":"CVE-2013-0599","CVE":"CVE-2013-0599","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"599","Ordinal":"1","NoteData":"IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.","Type":"Description","Title":"CVE-2013-0599"},{"CveYear":"2013","CveId":"599","Ordinal":"2","NoteData":"2013-05-28","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"599","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}