CVE-2011-4435

IBM DB2 Tools for z/OS 2.3.0 - Information Disclosure via Directory Browsing

Title source: llm
STIX 2.1

Description

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent directory browsing, which allows remote attackers to obtain sensitive information via HTTP requests.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1PM41190
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46487
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026278

Scores

EPSS 0.0123
EPSS Percentile 65.5%

Details

CWE
CWE-264
Status published
Products (1)
ibm/db2_tools_for_z\/os 2.3.0
Published Nov 11, 2011
Tracked Since Feb 18, 2026