Lucene search

K
ibmIBM13A374998A8F0D3986E14E68C6F321D646596A684119D5CB99B71C1DFD3FB72D
HistoryJul 16, 2018 - 5:29 p.m.

Security Bulletin: IBM Security Access Manager appliances are affected by a vulnerability in OpenLDAP (CVE-2015-6908)

2018-07-1617:29:01
www.ibm.com
11

0.947 High

EPSS

Percentile

99.3%

Summary

IBM Security Access Manager appliances use OpenLDAP. A vulnerability has been identified in OpenLDAP that affects the IBM Security Access Manager appliances.

IBM Security Access Manager has addressed this vulnerability.

Vulnerability Details

CVEID: CVE-2015-6908 DESCRIPTION: OpenLDAP is vulnerable to a denial of service, caused by an assertion error in the ber_get_next() function. By sending a specially-crafted packet, a remote attacker could exploit this vulnerability to cause the slapd service to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/106296 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected IBM Security Access Manager Appliance

|

Affected Versions

—|—
IBM Security Access Manager | 9.0 - 9.0.2.1
IBM Security Access Manager for Web | 8.0 - 8.0.1.6
IBM Security Access Manager for Mobile | 8.0 - 8.0.1.6

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation

—|—|—|—
IBM Security Access Manager for Web | 8.0 - 8.0.1.6 | IJ00151 | Upgrade to 8.0.1.7:
8.0.1-ISS-WGA-FP0007
IBM Security Access Manager for Mobile | 8.0 - 8.0.1.6 | IJ00157 |

Upgrade to 8.0.1.7:

8.0.1-ISS-ISAM-FP0007

IBM Security Access Manager | 9.0 - 9.0.2.1 | IJ00151 |

Upgrade to 9.0.3.0:

9.0.3.0-ISS-ISAM-FP0000

Workarounds and Mitigations

None.