First published: Tue May 28 2013(Updated: )
IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Directory Server | <=5.1.1.2 | |
IBM Tivoli Directory Server | =5.1.1 | |
IBM Tivoli Directory Server | =5.1.1.1 | |
IBM Tivoli Directory Server | <=5.2.1 | |
IBM Tivoli Directory Server | =5.2 | |
IBM Tivoli Directory Server | =5.2.0.1 | |
IBM Tivoli Directory Server | =5.2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0599 has a medium severity rating due to its potential to expose sensitive information.
To address CVE-2013-0599, it is recommended to upgrade IBM Rational Directory Server to the latest version that is not affected.
CVE-2013-0599 impacts IBM Rational Directory Server versions 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1.
CVE-2013-0599 is an information disclosure vulnerability that allows unauthorized access to debug information.
Yes, CVE-2013-0599 can be exploited by remote attackers through crafted parameter paths.