cbcvebase.
CVE-2011-2759
published 2011-07-17

CVE-2011-2759: The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off…

medium5CVSS 3.1
AVNACLAuNCPINAN
The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmtivoli_directory_server
ibmtivoli_directory_server
ibmtivoli_directory_server
ibmtivoli_directory_server