Lucene search

K
ibmIBME7B1F3C0D1894682C1143173C8B401DB9C186F58F2E3A53BAF7F282B2FFCBEBC
HistorySep 10, 2019 - 1:09 a.m.

Security Bulletin: IBM Security Access Manager vulnerable to Slow HTTP Attack (CVE-2019-4036)

2019-09-1001:09:49
www.ibm.com
6

0.001 Low

EPSS

Percentile

36.0%

Summary

The IBM Security Access Manager product can be attacked using the Slowloris Denial of service attack

Vulnerability Details

CVEID: CVE-2019-4036 DESCRIPTION: IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156159&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

All Supported versions

Remediation/Fixes

None

Workarounds and Mitigations

The mitigations are documented in the troubleshooting document <https://www.ibm.com/support/pages/how-can-i-protect-ibm-security-access-manager-against-slow-http-attack&gt;

CPENameOperatorVersion
ibm security access managereqany

0.001 Low

EPSS

Percentile

36.0%

Related for E7B1F3C0D1894682C1143173C8B401DB9C186F58F2E3A53BAF7F282B2FFCBEBC