CVE-2011-1820

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.7 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
ibmtivoli_directory_server
5.2.0
ibmtivoli_directory_server
5.2.0.4
ibmtivoli_directory_server
6.0
ibmtivoli_directory_server
6.0.0.0
ibmtivoli_directory_server
6.0.0.1
ibmtivoli_directory_server
6.0.0.7
ibmtivoli_directory_server
6.0.0.8
ibmtivoli_directory_server
6.0.0.14
ibmtivoli_directory_server
6.0.0.19
ibmtivoli_directory_server
6.0.0.33
ibmtivoli_directory_server
6.0.0.41
ibmtivoli_directory_server
6.0.0.45
ibmtivoli_directory_server
6.0.0.52
ibmtivoli_directory_server
6.0.0.53
ibmtivoli_directory_server
6.0.0.54
ibmtivoli_directory_server
6.0.0.55
ibmtivoli_directory_server
6.0.0.56
ibmtivoli_directory_server
6.0.0.57
ibmtivoli_directory_server
6.0.0.58
ibmtivoli_directory_server
6.0.0.59
ibmtivoli_directory_server
6.0.0.60
ibmtivoli_directory_server
6.0.0.61
ibmtivoli_directory_server
6.0.0.62
ibmtivoli_directory_server
6.0.0.63
ibmtivoli_directory_server
6.0.0.64
ibmtivoli_directory_server
6.0.0.65
ibmtivoli_directory_server
6.0.0.66
ibmtivoli_directory_server
6.1.0.0
ibmtivoli_directory_server
6.1.0.1
ibmtivoli_directory_server
6.1.0.2
ibmtivoli_directory_server
6.1.0.3
ibmtivoli_directory_server
6.1.0.4
ibmtivoli_directory_server
6.1.0.5
ibmtivoli_directory_server
6.1.0.6
ibmtivoli_directory_server
6.1.0.7
ibmtivoli_directory_server
6.1.0.8
ibmtivoli_directory_server
6.1.0.9
ibmtivoli_directory_server
6.1.0.10
ibmtivoli_directory_server
6.1.0.11
ibmtivoli_directory_server
6.1.0.12
ibmtivoli_directory_server
6.1.0.13
ibmtivoli_directory_server
6.1.0.14
ibmtivoli_directory_server
6.1.0.15
ibmtivoli_directory_server
6.1.0.17
ibmtivoli_directory_server
6.1.0.18
ibmtivoli_directory_server
6.1.0.19
ibmtivoli_directory_server
6.1.0.20
ibmtivoli_directory_server
6.1.0.21
ibmtivoli_directory_server
6.1.0.22
ibmtivoli_directory_server
6.1.0.23
ibmtivoli_directory_server
6.1.0.24
ibmtivoli_directory_server
6.1.0.25
ibmtivoli_directory_server
6.1.0.26
ibmtivoli_directory_server
6.1.0.27
ibmtivoli_directory_server
6.1.0.28
ibmtivoli_directory_server
6.1.0.29
ibmtivoli_directory_server
6.1.0.30
ibmtivoli_directory_server
6.1.0.31
ibmtivoli_directory_server
6.1.0.32
ibmtivoli_directory_server
6.1.0.33
ibmtivoli_directory_server
6.1.0.34
ibmtivoli_directory_server
6.1.0.35
ibmtivoli_directory_server
6.1.0.36
ibmtivoli_directory_server
6.1.0.37
ibmtivoli_directory_server
6.1.0.38
ibmtivoli_directory_server
6.1.0.39
ibmtivoli_directory_server
6.2.0.0
ibmtivoli_directory_server
6.2.0.1
ibmtivoli_directory_server
6.2.0.2
ibmtivoli_directory_server
6.2.0.3
ibmtivoli_directory_server
6.2.0.4
ibmtivoli_directory_server
6.2.0.5
ibmtivoli_directory_server
6.2.0.6
ibmtivoli_directory_server
6.2.0.7
ibmtivoli_directory_server
6.2.0.8
ibmtivoli_directory_server
6.2.0.10
ibmtivoli_directory_server
6.2.0.11
ibmtivoli_directory_server
6.2.0.12
ibmtivoli_directory_server
6.2.0.13
ibmtivoli_directory_server
6.2.0.14
ibmtivoli_directory_server
6.2.0.15
ibmtivoli_directory_server
6.3.0.0
ibmtivoli_directory_server
6.3.0.1
ibmtivoli_directory_server
6.3.0.2
𝑥
= Vulnerable software versions