CVE-2015-2019

low
Published 2015-06-28 · Modified 2026-05-06
CVSS v3
VIR risk
2.1

Description

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
ibm ibmtivoli_directory_server6.0
ibm ibmtivoli_directory_server6.1.0
ibm ibmtivoli_directory_server6.2.0.0
ibm ibmtivoli_directory_server6.3.0.0
ibm ibmtivoli_directory_server6.3.1.0
ibm ibmtivoli_directory_server6.4.0

References

CWEs

CWE-17

💬 Discuss CVE-2015-2019 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.