CVE-2013-6305
IBM Platform Symphony 5.2-6.1.0.1 - Sensitive Information Exposure via Shared Credentials Encryption Key
Title source: llmDescription
IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/88536
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=isg3T1020528
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/102262
Scores
EPSS
0.0062
EPSS Percentile
46.1%
Details
CWE
CWE-310
Status
published
Products (2)
ibm/platform_symphony
5.2
ibm/platform_symphony
6.1.0.1
Published
Jan 21, 2014
Tracked Since
Feb 18, 2026