CVE-2013-0599
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the…
Does this matter?
Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/rational directory server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21637151Vendor Advisory
- http://www.securityfocus.com/bid/60107
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83613
- http://www-01.ibm.com/support/docview.wss?uid=swg21637151Vendor Advisory
- http://www.securityfocus.com/bid/60107
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83613
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.