| |
Vulnerability CVE-2013-0534
Published: 2013-06-21
Description: |
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory. |
Type:
CWE-255 (Credentials Management)
CVSS2 => (AV:L/AC:M/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
1.9/10 |
2.9/10 |
3.4/10 |
Exploit range |
Attack complexity |
Authentication |
Local |
Medium |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
http://xforce.iss.net/xforce/xfdb/82656
http://www-01.ibm.com/support/docview.wss?uid=swg21635218
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|