CVE-2003-1282
IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other…
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://www.iss.net/security_center/static/11016.php
- http://www.securiteam.com/securitynews/5CP061F8VS.htmlVendor Advisory
- http://www.securitytracker.com/id?1005890
- http://www.iss.net/security_center/static/11016.php
- http://www.securiteam.com/securitynews/5CP061F8VS.htmlVendor Advisory
- http://www.securitytracker.com/id?1005890
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.