CVE-2013-6305

IBM Platform Symphony 5.2-6.1.0.1 - Sensitive Information Exposure via Shared Credentials Encryption Key

Title source: llm
STIX 2.1

Description

IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/88536
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102262

Scores

EPSS 0.0062
EPSS Percentile 46.1%

Details

CWE
CWE-310
Status published
Products (2)
ibm/platform_symphony 5.2
ibm/platform_symphony 6.1.0.1
Published Jan 21, 2014
Tracked Since Feb 18, 2026