Vulnerability Bulletins

Security Bulletin: IBM InfoSphere Information Server sometimes records sensitive data when an installation fails (CVE-2013-5440)


System information

   
Affected software IBM

Description

In certain situations after a specific error has been encountered and InfoSphere Information Server installation fails, sensitive data is recorded in a file. For releases 8.5 and earlier this vulnerability can occur only when updating an existing installation with maintenance. For releases 8.7and onwards, this vulnerability can occur when performing all types of installations including new installations, adding of components not previously installed and updating an existing installation with

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_infosphere_information_server_sometimes_records_sensitive_data_when_an_installation_fails_cve_2013_54401?lang=en_us

Standar resources

Property Value
CVE CVE-2013-5440 ,CVE-2014-0873 ,CVE-2013-4002 ,CVE-2013-5825 ,CVE-2013-5372 ,CVE-2014-0416 ,CVE-2014-0411 ,CVE-2013-4353 ,CVE-2013-6450 ,CVE-2013-6449 ,CVE-2013-6734 and CVE-2014-0890.

Version history

Version Comments Date
1.0 Advisory issued 2014-03-12
Ministerio de Defensa
CNI
CCN
CCN-CERT