CVE-2011-1820

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.7 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
ibmtivoli_directory_server
5.2.0
ibmtivoli_directory_server
5.2.0.4
ibmtivoli_directory_server
6.0
ibmtivoli_directory_server
6.0.0.0
ibmtivoli_directory_server
6.0.0.1
ibmtivoli_directory_server
6.0.0.7
ibmtivoli_directory_server
6.0.0.8
ibmtivoli_directory_server
6.0.0.14
ibmtivoli_directory_server
6.0.0.19
ibmtivoli_directory_server
6.0.0.33
ibmtivoli_directory_server
6.0.0.41
ibmtivoli_directory_server
6.0.0.45
ibmtivoli_directory_server
6.0.0.52
ibmtivoli_directory_server
6.0.0.53
ibmtivoli_directory_server
6.0.0.54
ibmtivoli_directory_server
6.0.0.55
ibmtivoli_directory_server
6.0.0.56
ibmtivoli_directory_server
6.0.0.57
ibmtivoli_directory_server
6.0.0.58
ibmtivoli_directory_server
6.0.0.59
ibmtivoli_directory_server
6.0.0.60
ibmtivoli_directory_server
6.0.0.61
ibmtivoli_directory_server
6.0.0.62
ibmtivoli_directory_server
6.0.0.63
ibmtivoli_directory_server
6.0.0.64
ibmtivoli_directory_server
6.0.0.65
ibmtivoli_directory_server
6.0.0.66
ibmtivoli_directory_server
6.1.0.0
ibmtivoli_directory_server
6.1.0.1
ibmtivoli_directory_server
6.1.0.2
ibmtivoli_directory_server
6.1.0.3
ibmtivoli_directory_server
6.1.0.4
ibmtivoli_directory_server
6.1.0.5
ibmtivoli_directory_server
6.1.0.6
ibmtivoli_directory_server
6.1.0.7
ibmtivoli_directory_server
6.1.0.8
ibmtivoli_directory_server
6.1.0.9
ibmtivoli_directory_server
6.1.0.10
ibmtivoli_directory_server
6.1.0.11
ibmtivoli_directory_server
6.1.0.12
ibmtivoli_directory_server
6.1.0.13
ibmtivoli_directory_server
6.1.0.14
ibmtivoli_directory_server
6.1.0.15
ibmtivoli_directory_server
6.1.0.17
ibmtivoli_directory_server
6.1.0.18
ibmtivoli_directory_server
6.1.0.19
ibmtivoli_directory_server
6.1.0.20
ibmtivoli_directory_server
6.1.0.21
ibmtivoli_directory_server
6.1.0.22
ibmtivoli_directory_server
6.1.0.23
ibmtivoli_directory_server
6.1.0.24
ibmtivoli_directory_server
6.1.0.25
ibmtivoli_directory_server
6.1.0.26
ibmtivoli_directory_server
6.1.0.27
ibmtivoli_directory_server
6.1.0.28
ibmtivoli_directory_server
6.1.0.29
ibmtivoli_directory_server
6.1.0.30
ibmtivoli_directory_server
6.1.0.31
ibmtivoli_directory_server
6.1.0.32
ibmtivoli_directory_server
6.1.0.33
ibmtivoli_directory_server
6.1.0.34
ibmtivoli_directory_server
6.1.0.35
ibmtivoli_directory_server
6.1.0.36
ibmtivoli_directory_server
6.1.0.37
ibmtivoli_directory_server
6.1.0.38
ibmtivoli_directory_server
6.1.0.39
ibmtivoli_directory_server
6.2.0.0
ibmtivoli_directory_server
6.2.0.1
ibmtivoli_directory_server
6.2.0.2
ibmtivoli_directory_server
6.2.0.3
ibmtivoli_directory_server
6.2.0.4
ibmtivoli_directory_server
6.2.0.5
ibmtivoli_directory_server
6.2.0.6
ibmtivoli_directory_server
6.2.0.7
ibmtivoli_directory_server
6.2.0.8
ibmtivoli_directory_server
6.2.0.10
ibmtivoli_directory_server
6.2.0.11
ibmtivoli_directory_server
6.2.0.12
ibmtivoli_directory_server
6.2.0.13
ibmtivoli_directory_server
6.2.0.14
ibmtivoli_directory_server
6.2.0.15
ibmtivoli_directory_server
6.3.0.0
ibmtivoli_directory_server
6.3.0.1
ibmtivoli_directory_server
6.3.0.2
𝑥
= Vulnerable software versions