Lucene search

K
cveIbmCVE-2013-4025
HistorySep 25, 2013 - 10:31 a.m.

CVE-2013-4025

2013-09-2510:31:29
CWE-264
ibm
web.nvd.nist.gov
26
ibm
data studio
web console
optim performance manager
infosphere
optim configuration manager
db2
remote access
vulnerability
cve-2013-4025

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

61.7%

IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Affected configurations

Nvd
Node
ibmdata_studio_web_consoleMatch3.1.0
OR
ibmdb2_recovery_expertMatch2.0
OR
ibminfosphere_optim_configuration_managerMatch2.0
OR
ibminfosphere_optim_configuration_managerMatch2.1
OR
ibmoptim_performance_managerMatch5.1.0
VendorProductVersionCPE
ibmdata_studio_web_console3.1.0cpe:2.3:a:ibm:data_studio_web_console:3.1.0:*:*:*:*:*:*:*
ibmdb2_recovery_expert2.0cpe:2.3:a:ibm:db2_recovery_expert:2.0:*:*:*:*:*:*:*
ibminfosphere_optim_configuration_manager2.0cpe:2.3:a:ibm:infosphere_optim_configuration_manager:2.0:*:*:*:*:*:*:*
ibminfosphere_optim_configuration_manager2.1cpe:2.3:a:ibm:infosphere_optim_configuration_manager:2.1:*:*:*:*:*:*:*
ibmoptim_performance_manager5.1.0cpe:2.3:a:ibm:optim_performance_manager:5.1.0:*:*:*:*:*:*:*

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

61.7%

Related for CVE-2013-4025