CVE-2011-2759: Infoleak
The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2759?
CVE-2011-2759 has a moderate severity rating, indicating it poses a significant risk under certain conditions.
How do I fix CVE-2011-2759?
To fix CVE-2011-2759, upgrade IBM Tivoli Directory Server to version 6.2.0.3-TIV-ITDS-IF0004 or later.
What products are affected by CVE-2011-2759?
CVE-2011-2759 affects IBM Tivoli Directory Server versions 6.2.0.0 through 6.2.0.2.
Who can exploit CVE-2011-2759?
CVE-2011-2759 can be exploited by remote attackers with access to an unattended workstation.
What type of vulnerability is CVE-2011-2759?
CVE-2011-2759 is a vulnerability related to improper input handling due to missing autocomplete attributes on authentication fields.