CVE-2011-1822
published 2011-04-21CVE-2011-1822: The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.29%
20.6th percentile
The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_directory_server | — | — |
| ibm | tivoli_directory_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4580 JBoss Enterprise Portal Platform: Multiple XSS flaws
bugzilla·2011-12-07·CVSS 4.3
CVE-2011-4580 [MEDIUM] CVE-2011-4580 JBoss Enterprise Portal Platform: Multiple XSS flaws
CVE-2011-4580 JBoss Enterprise Portal Platform: Multiple XSS flaws
Multiple cross-site scripting (XSS) flaws were found in JBoss Enterprise Portal Platform (EPP). If a remote attacker could trick a user, who was logged into EPP, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's EPP session.
Discussion:
This issue has been addressed in following products:
JBoss Enterprise Portal Platform 5.2.0
Via RHSA-2011:1822 https://rhn.redhat.com/errata/RHSA-2011-1822.html
Bugzilla
CVE-2011-2941 JBoss Enterprise Portal Platform: open URL redirect
bugzilla·2011-08-22·CVSS 5.8
CVE-2011-2941 [MEDIUM] CVE-2011-2941 JBoss Enterprise Portal Platform: open URL redirect
CVE-2011-2941 JBoss Enterprise Portal Platform: open URL redirect
An open URL redirect exists on the login page of JBoss Enterprise Portal Platform. This vulnerability allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter.
Acknowledgements:
Red Hat would like to thank Christopher Hartley of The Ohio State University for reporting this issue.
Discussion:
This issue has been addressed in following products:
JBoss Enterprise Portal Platform 5.2.0
Via RHSA-2011:1822 https://rhn.redhat.com/errata/RHSA-2011-1822.html
2011-04-21
Published