CVE-2011-2758: Medium severity IBM Tivoli Directory Server vulnerability
Published Jul 17, 2011
·Updated
IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.
Affected Software
4 affected components
IBM Tivoli Directory Server=6.2
IBM Tivoli Directory Server=6.2.0.0
IBM Tivoli Directory Server=6.2.0.1
IBM Tivoli Directory Server=6.2.0.2
Event History
Jul 17, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2758?
CVE-2011-2758 is rated as a high severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2011-2758?
To fix CVE-2011-2758, upgrade IBM Tivoli Directory Server to version 6.2.0.3-TIV-ITDS-IF0004 or later.
3
What does CVE-2011-2758 affect?
CVE-2011-2758 affects IBM Tivoli Directory Server versions 6.2.0.0 to 6.2.0.2.
4
What type of attacks can exploit CVE-2011-2758?
CVE-2011-2758 can be exploited by remote attackers who can access LDAP Server log files without authentication.
5
What information can be exposed by CVE-2011-2758?
CVE-2011-2758 can expose sensitive information stored in the LDAP Server log files.