CVE-2011-1820

EUVD-2011-1818
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditing of extended operations, which might allow attackers to obtain sensitive information by reading the audit log.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.7 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
ibmtivoli_directory_server
5.2.0
ibmtivoli_directory_server
5.2.0.4
ibmtivoli_directory_server
6.0
ibmtivoli_directory_server
6.0.0.0
ibmtivoli_directory_server
6.0.0.1
ibmtivoli_directory_server
6.0.0.7
ibmtivoli_directory_server
6.0.0.8
ibmtivoli_directory_server
6.0.0.14
ibmtivoli_directory_server
6.0.0.19
ibmtivoli_directory_server
6.0.0.33
ibmtivoli_directory_server
6.0.0.41
ibmtivoli_directory_server
6.0.0.45
ibmtivoli_directory_server
6.0.0.52
ibmtivoli_directory_server
6.0.0.53
ibmtivoli_directory_server
6.0.0.54
ibmtivoli_directory_server
6.0.0.55
ibmtivoli_directory_server
6.0.0.56
ibmtivoli_directory_server
6.0.0.57
ibmtivoli_directory_server
6.0.0.58
ibmtivoli_directory_server
6.0.0.59
ibmtivoli_directory_server
6.0.0.60
ibmtivoli_directory_server
6.0.0.61
ibmtivoli_directory_server
6.0.0.62
ibmtivoli_directory_server
6.0.0.63
ibmtivoli_directory_server
6.0.0.64
ibmtivoli_directory_server
6.0.0.65
ibmtivoli_directory_server
6.0.0.66
ibmtivoli_directory_server
6.1.0.0
ibmtivoli_directory_server
6.1.0.1
ibmtivoli_directory_server
6.1.0.2
ibmtivoli_directory_server
6.1.0.3
ibmtivoli_directory_server
6.1.0.4
ibmtivoli_directory_server
6.1.0.5
ibmtivoli_directory_server
6.1.0.6
ibmtivoli_directory_server
6.1.0.7
ibmtivoli_directory_server
6.1.0.8
ibmtivoli_directory_server
6.1.0.9
ibmtivoli_directory_server
6.1.0.10
ibmtivoli_directory_server
6.1.0.11
ibmtivoli_directory_server
6.1.0.12
ibmtivoli_directory_server
6.1.0.13
ibmtivoli_directory_server
6.1.0.14
ibmtivoli_directory_server
6.1.0.15
ibmtivoli_directory_server
6.1.0.17
ibmtivoli_directory_server
6.1.0.18
ibmtivoli_directory_server
6.1.0.19
ibmtivoli_directory_server
6.1.0.20
ibmtivoli_directory_server
6.1.0.21
ibmtivoli_directory_server
6.1.0.22
ibmtivoli_directory_server
6.1.0.23
ibmtivoli_directory_server
6.1.0.24
ibmtivoli_directory_server
6.1.0.25
ibmtivoli_directory_server
6.1.0.26
ibmtivoli_directory_server
6.1.0.27
ibmtivoli_directory_server
6.1.0.28
ibmtivoli_directory_server
6.1.0.29
ibmtivoli_directory_server
6.1.0.30
ibmtivoli_directory_server
6.1.0.31
ibmtivoli_directory_server
6.1.0.32
ibmtivoli_directory_server
6.1.0.33
ibmtivoli_directory_server
6.1.0.34
ibmtivoli_directory_server
6.1.0.35
ibmtivoli_directory_server
6.1.0.36
ibmtivoli_directory_server
6.1.0.37
ibmtivoli_directory_server
6.1.0.38
ibmtivoli_directory_server
6.1.0.39
ibmtivoli_directory_server
6.2.0.0
ibmtivoli_directory_server
6.2.0.1
ibmtivoli_directory_server
6.2.0.2
ibmtivoli_directory_server
6.2.0.3
ibmtivoli_directory_server
6.2.0.4
ibmtivoli_directory_server
6.2.0.5
ibmtivoli_directory_server
6.2.0.6
ibmtivoli_directory_server
6.2.0.7
ibmtivoli_directory_server
6.2.0.8
ibmtivoli_directory_server
6.2.0.10
ibmtivoli_directory_server
6.2.0.11
ibmtivoli_directory_server
6.2.0.12
ibmtivoli_directory_server
6.2.0.13
ibmtivoli_directory_server
6.2.0.14
ibmtivoli_directory_server
6.2.0.15
ibmtivoli_directory_server
6.3.0.0
ibmtivoli_directory_server
6.3.0.1
ibmtivoli_directory_server
6.3.0.2
𝑥
= Vulnerable software versions