Executive brief
IBM Security Directory Integrator, a tool used to synchronize and manage identity data across different systems, is vulnerable to information disclosure. A remote attacker can trigger technical error messages that reveal sensitive internal system details. This information could be used to plan more sophisticated attacks against the organization's infrastructure.
Technical details
The vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). It occurs when the application returns overly verbose technical error messages to the client's browser during certain failure conditions. A remote, unauthenticated attacker can exploit this by sending crafted requests that trigger these errors, potentially revealing configuration details, stack traces, or other internal metadata. This disclosure facilitates reconnaissance for subsequent exploitation. The issue is resolved in versions 7.2.0.15 and 10.0.0.3.
Affected products
- IBM Security Directory Integrator (SDI) 7.2.0.0 - 7.2.0.14
- IBM Security Directory Integrator (SDI) 10.0.0.0 - 10.0.0.2
Timeline
- 2026-04-08: advisory: Initial IBM publication
- 2026-05-27: disclosed: NVD publication