Executive Summary

Informations
Name CVE-2011-1820 First vendor Publication 2011-04-21
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:S/C:P/I:N/A:N)
Cvss Base Score 1.7 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 3.1 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1820

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-200 Information Exposure

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 84

OpenVAS Exploits

Date Description
2011-05-02 Name : IBM Tivoli Directory Server SASL Bind Request Remote Code Execution Vulnerabi...
File : nvt/secpod_ibm_tivoli_dir_server_code_exec_vuln.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
72692 IBM Tivoli Directory Server TDS Proxy Server ibm-auditAttributesOnGroupEvalOp...

Sources (Detail)

http://secunia.com/advisories/44184
http://securitytracker.com/id?1025358
http://www.ibm.com/support/docview.wss?uid=swg1IO14023
http://www.ibm.com/support/docview.wss?uid=swg1IO14025
http://www.ibm.com/support/docview.wss?uid=swg1IO14028
http://www.ibm.com/support/docview.wss?uid=swg1IO14043
http://www.ibm.com/support/docview.wss?uid=swg1IO14044
http://www.ibm.com/support/docview.wss?uid=swg21496086
http://www.ibm.com/support/docview.wss?uid=swg24029659
http://www.ibm.com/support/docview.wss?uid=swg24029660
http://www.ibm.com/support/docview.wss?uid=swg24029661
http://www.ibm.com/support/docview.wss?uid=swg24029663
http://www.ibm.com/support/docview.wss?uid=swg24029672
https://exchange.xforce.ibmcloud.com/vulnerabilities/66712
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
Date Informations
2024-11-28 23:05:25
  • Multiple Updates
2024-11-28 12:25:40
  • Multiple Updates
2021-05-04 12:14:27
  • Multiple Updates
2021-04-22 01:15:44
  • Multiple Updates
2020-05-23 00:28:30
  • Multiple Updates
2017-08-17 09:23:32
  • Multiple Updates
2016-04-26 20:45:00
  • Multiple Updates
2013-05-10 22:59:51
  • Multiple Updates