← Vulnerability feed

Vulnerability record · CVE-2013-5461 · published 27 April 2018

CVE-2013-5461: Ibm endpoint manager for remote control vulnerability

Ibm · Endpoint Manager For Remote Control

IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.

8.8 CVSS 3.0 High EPSS 2.4% · top 16.8% CWE-255 · CWE-255
8.8CVSS 3.0 base score, v2 4.0
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-5461 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2012-4823Ibm java vulnerabilityUnspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and ea…EPSS 6.9%9.3CVE-2012-4821Ibm java vulnerabilityMultiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …EPSS 6.9%9.3CVE-2012-4822Ibm java vulnerabilityMultiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 …EPSS 6.9%9.3CVE-2012-4820Ibm java vulnerabilityUnspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and ea…EPSS 5.1%8.8CVE-2015-4952Ibm endpoint manager for remote control vulnerabilityThe on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via u…EPSS 1.9%6.5CVE-2013-3033Ibm tivoli remote control sql injection vulnerabilitySQL injection vulnerability in the server component in IBM Tivoli Remote Control 5.1.2 before 5.1.2-TIV-TRC512-IF0015 allows remote authenticated use…EPSS 0.96%8.8CVE-2014-1812Microsoft Windows Group Policy Preferences credential exposure and privilege escalationGroup Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any auth…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2013-5461), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.