Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.902507
Categoría:Buffer overflow
Título:IBM Tivoli Directory Server SASL Bind Request RCE Vulnerability
Resumen:IBM Tivoli Directory Server is prone to a remote code execution (RCE) vulnerability.
Descripción:Summary:
IBM Tivoli Directory Server is prone to a remote code execution (RCE) vulnerability.

Vulnerability Insight:
The flaw is caused by a stack overflow error in the 'ibmslapd.exe' component
when allocating a buffer via the 'ber_get_int()' function within
'libibmldap.dll' while handling LDAP CRAM-MD5 packets, which could be
exploited by remote unauthenticated attackers to execute arbitrary code with
SYSTEM privileges.

Vulnerability Impact:
Successful exploitation could allow remote attackers to execute arbitrary
code within the context of the affected application or retrieve potentially sensitive information.

Affected Software/OS:
IBM Tivoli Directory Server 5.2 before 5.2.0.5-TIV-ITDS-IF0010,
6.0 before 6.0.0.67 (6.0.0.8-TIV-ITDS-IF0009),
6.1 before 6.1.0.40 (6.1.0.5-TIV-ITDS-IF0003),
6.2 before 6.2.0.16 (6.2.0.3-TIV-ITDS-IF0002),
and 6.3 before 6.3.0.3

Solution:
Apply Vendor patches.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1206
AIX APAR: IO14009
http://www.ibm.com/support/docview.wss?uid=swg1IO14009
AIX APAR: IO14010
http://www.ibm.com/support/docview.wss?uid=swg1IO14010
AIX APAR: IO14013
http://www.ibm.com/support/docview.wss?uid=swg1IO14013
AIX APAR: IO14045
http://www.ibm.com/support/docview.wss?uid=swg1IO14045
AIX APAR: IO14046
http://www.ibm.com/support/docview.wss?uid=swg1IO14046
http://securitytracker.com/id?1025358
http://secunia.com/advisories/44184
http://securityreason.com/securityalert/8213
XForce ISS Database: ibm-tds-ibmslapd-bo(66711)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66711
Common Vulnerability Exposure (CVE) ID: CVE-2011-1820
AIX APAR: IO14023
http://www.ibm.com/support/docview.wss?uid=swg1IO14023
AIX APAR: IO14025
http://www.ibm.com/support/docview.wss?uid=swg1IO14025
AIX APAR: IO14028
http://www.ibm.com/support/docview.wss?uid=swg1IO14028
AIX APAR: IO14043
http://www.ibm.com/support/docview.wss?uid=swg1IO14043
AIX APAR: IO14044
http://www.ibm.com/support/docview.wss?uid=swg1IO14044
XForce ISS Database: ibm-tds-proxyserver-info-disclosure(66712)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66712
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.