CVE-2013-6305
IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by…
Does this matter?
Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- ibm/platform symphony
- Source
- psirt@us.ibm.com
References
- http://osvdb.org/102262
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1020528Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88536
- http://osvdb.org/102262
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1020528Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88536
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.