Lucene search

K
ibmIBM53C63877D4D83FDEF5C3AD4646A439DCFFDECA25B806663775ACF56B851D3F44
HistoryJun 16, 2018 - 10:04 p.m.

Security Bulletin: IBM Security Access Manager Appliance is affected by OpenSSH vulnerabilities

2018-06-1622:04:58
www.ibm.com
52

0.107 Low

EPSS

Percentile

95.1%

Summary

IBM Security Access Manager Appliance has addressed the following vulnerabilities in the OpenSSH libraries used on the appliance.

Vulnerability Details

CVEID: CVE-2016-6515**
DESCRIPTION:** OpenSSH is vulnerable to a denial of service, caused by the failure to limit password lengths for password authentication by the auth_password function. A remote attacker could exploit this vulnerability using an overly long string to consume all available CPU resources.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115911 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID: CVE-2016-6210**
DESCRIPTION:** OpenSSH could allow a remote attacker to obtain sensitive information, caused by the increased amount of time to calculate SHA256/SHA512 hash than BLOWFISH hash. An attacker could exploit this vulnerability using a covert timing channel to enumerate users on system that runs SSHD.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115128 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2016-10009**
DESCRIPTION:** OpenSSH could allow a remote authenticated attacker to execute arbitrary code on the system, caused by the loading of a specially crafted PKCS#11 module across a forwarded agent channel. An attacker could exploit this vulnerability to write files or execute arbitrary code on the system.
CVSS Base Score: 6.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119828 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected IBM Security Access Manager Appliance

|

Affected Versions

—|—
IBM Security Access Manager | 9.0.3.0-9.0.3.1

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation

—|—|—|—
IBM Security Access Manager| 9.0.3.0 - 9.0.3.1| IJ01544| Upgrade to 9.0.4.0:
9.0.4-ISS-ISAM-FP0000

Workarounds and Mitigations

None