CVE-2013-5420: Low severity ibm security access manager vulnerability
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5420?
CVE-2013-5420 has a medium severity rating due to its potential for unauthorized access to sensitive log files.
Who is affected by CVE-2013-5420?
CVE-2013-5420 affects users of IBM Security Access Manager for Enterprise Single Sign-On version 8.2 before Ifix 6.
How can I mitigate CVE-2013-5420?
To mitigate CVE-2013-5420, ensure that Ifix 6 or later is applied to the IBM Security Access Manager for Enterprise Single Sign-On.
What is the impact of CVE-2013-5420?
The impact of CVE-2013-5420 allows remote authenticated users with helpdesk privileges to access and potentially exploit sensitive log files.
Is there a patch available for CVE-2013-5420?
Yes, a patch is available by upgrading to Ifix 6 or a later version of IBM Security Access Manager for Enterprise Single Sign-On.