CVE-2015-1972: Infoleak
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1972?
CVE-2015-1972 is classified as a medium severity vulnerability that can expose sensitive information to remote attackers.
How do I fix CVE-2015-1972?
To fix CVE-2015-1972, apply the latest iFix for your specific version of IBM Tivoli Security Directory Server as listed in the official documentation.
What versions of IBM Tivoli Directory Server are affected by CVE-2015-1972?
CVE-2015-1972 affects IBM Tivoli Directory Server versions 6.0, 6.1, 6.2, 6.3, 6.3.1, and 6.4 before their respective iFix updates.
What type of attack does CVE-2015-1972 exploit?
CVE-2015-1972 exploits the ability of remote attackers to send crafted POST requests to obtain sensitive error-log information.
Can CVE-2015-1972 lead to data breaches?
Yes, the exposure of sensitive error-log information through CVE-2015-1972 can potentially lead to data breaches if exploited by attackers.