Lucene search

K
ibmIBM7B443EE6FE6495AB40EB18D47B9F1700A844532C4A40A25E4DB617D9AE4F8CC6
HistoryAug 13, 2019 - 7:08 p.m.

Security Bulletin: IBM MQ Appliance is affected by OpenSSH vulnerabilities

2019-08-1319:08:35
www.ibm.com
24

0.107 Low

EPSS

Percentile

95.1%

Summary

IBM MQ Appliance has addressed vulnerabilities in OpenSSH.

Vulnerability Details

CVEID: CVE-2016-10009 DESCRIPTION: OpenSSH could allow a remote authenticated attacker to execute arbitrary code on the system, caused by the loading of a specially crafted PKCS#11 module across a forwarded agent channel. An attacker could exploit this vulnerability to write files or execute arbitrary code on the system.
CVSS Base Score: 6.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119828 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

CVEID: CVE-2016-6515 DESCRIPTION: OpenSSH is vulnerable to a denial of service, caused by the failure to limit password lengths for password authentication by the auth_password function. A remote attacker could exploit this vulnerability using an overly long string to consume all available CPU resources.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115911 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID: CVE-2016-6210 DESCRIPTION: OpenSSH could allow a remote attacker to obtain sensitive information, caused by the increased amount of time it takes to calculate SHA256/SHA512 hash rather than BLOWFISH hash. An attacker could exploit this vulnerability using a covert timing channel to enumerate users on a system that runs SSHD.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/115128 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Affected Products and Versions

IBM MQ Appliance 8.0

Maintenance levels 8.0.0.0 - 8.0.0.8

IBM MQ Appliance 9.0.x Continuous Delivery (CD) Release

Continuous delivery updates 9.0.1 - 9.0.4

Remediation/Fixes

IBM MQ Appliance 8.0

Apply fixpack 8.0.0.9

IBM MQ Appliance 9.0.x Continuous Delivery (CD) Release

Apply Continuous Delivery Release 9.0.5