1.9
CVE-2013-4025
- EPSS 0.48%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Data Studio Web Console Version 3.1.0
Ibm ≫ Db2 Recovery Expert Version 2.0
Ibm ≫ Infosphere Optim Configuration Manager Version 2.0
Ibm ≫ Infosphere Optim Configuration Manager Version 2.1
Ibm ≫ Optim Performance Manager Version 5.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.375 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:P/I:N/A:N
|
http://www-01.ibm.com/support/docview.wss?uid=swg21650504
https://exchange.xforce.ibmcloud.com/vulnerabilities/85933