IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability
BID:42015
Info
IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability
| Bugtraq ID: | 42015 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 26 2010 12:00AM |
| Updated: | Jul 28 2010 03:15PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
IBM Tivoli Directory Server 6.1 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability
IBM Tivoli Directory Server is prone to an information-disclosure vulnerability that may expose the DB2 admin password.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
IBM Tivoli Directory Server version 6.1 is vulnerable.
IBM Tivoli Directory Server is prone to an information-disclosure vulnerability that may expose the DB2 admin password.
Successful exploits will allow attackers to obtain sensitive information that may aid in further attacks.
IBM Tivoli Directory Server version 6.1 is vulnerable.
Exploit / POC
IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability
Attackers can exploit the issue using standard commands.
Attackers can exploit the issue using standard commands.
Solution / Fix
IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability
Solution:
Updates are available for this issue. Please see the references for details.
Solution:
Updates are available for this issue. Please see the references for details.
References
IBM Tivoli Directory Server DB2 Password Information Disclosure Vulnerability
References:
References: