CVE-2011-1822: Low severity IBM Tivoli Directory Server vulnerability
Published Apr 21, 2011
·Updated
The LDAPADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.
Affected Software
2 affected components
IBM Tivoli Directory Server=5.2.0
IBM Tivoli Directory Server=5.2.0.4
Remediation
Patch Available
Event History
Apr 21, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1822?
CVE-2011-1822 is classified as a medium severity vulnerability due to the potential exposure of sensitive information stored in cleartext.
2
How do I fix CVE-2011-1822?
To fix CVE-2011-1822, upgrade to IBM Tivoli Directory Server version 5.2.0.5-TIV-ITDS-IF0009 or later.
3
What systems are affected by CVE-2011-1822?
CVE-2011-1822 affects IBM Tivoli Directory Server versions 5.2.0 and 5.2.0.4.
4
What type of information is exposed in CVE-2011-1822?
CVE-2011-1822 exposes sensitive password information stored in the change log in cleartext SHA format.
5
Who can exploit CVE-2011-1822?
CVE-2011-1822 can potentially be exploited by local users with access to the change log.