CVE-2015-1959
Published Jun 28, 2015
Last updated 8 years ago
Overview
- Description
- IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly restrict encrypted files, which allows local users to obtain sensitive information or possibly have unspecified other impact via a (1) download or (2) upload action.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-284
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:tivoli_directory_server:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1EF905E9-DDA5-4369-AC6C-FD6E2573E667" }, { "criteria": "cpe:2.3:a:ibm:tivoli_directory_server:6.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06626F2E-605A-4AA0-839D-B035336453E1" }, { "criteria": "cpe:2.3:a:ibm:tivoli_directory_server:6.2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "653551D3-88A3-4E69-A1B1-64326BEF1F18" }, { "criteria": "cpe:2.3:a:ibm:tivoli_directory_server:6.3.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D48029C-3455-46A6-A8CA-8013A167979B" }, { "criteria": "cpe:2.3:a:ibm:tivoli_directory_server:6.3.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C36D4B16-30CE-4E1F-9DCE-B06C849D5751" }, { "criteria": "cpe:2.3:a:ibm:tivoli_directory_server:6.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44FBF236-512B-4CCC-A7B2-E32E47594A4F" } ], "operator": "OR" } ] } ]