CVE-2015-1959
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- ibm/tivoli directory server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21960659Patch, Vendor Advisory
- http://www.securityfocus.com/bid/75442
- http://www.securitytracker.com/id/1032734
- http://www-01.ibm.com/support/docview.wss?uid=swg21960659Patch, Vendor Advisory
- http://www.securityfocus.com/bid/75442
- http://www.securitytracker.com/id/1032734
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.