First published: Mon Dec 23 2013(Updated: )
The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager for Enterprise Single Sign-On | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5420 has a medium severity rating due to its potential for unauthorized access to sensitive log files.
CVE-2013-5420 affects users of IBM Security Access Manager for Enterprise Single Sign-On version 8.2 before Ifix 6.
To mitigate CVE-2013-5420, ensure that Ifix 6 or later is applied to the IBM Security Access Manager for Enterprise Single Sign-On.
The impact of CVE-2013-5420 allows remote authenticated users with helpdesk privileges to access and potentially exploit sensitive log files.
Yes, a patch is available by upgrading to Ifix 6 or a later version of IBM Security Access Manager for Enterprise Single Sign-On.