Lucene search

K
ibmIBMF1506A12BA45D6EFCDB8EFECB06034338F9DBB5C2E767720446EDFFCD5EEE7EC
HistoryJun 16, 2018 - 9:50 p.m.

Security Bulletin: IBM Security Access Manager appliances are affected by a vulnerability in OpenLDAP (CVE-2015-6908)

2018-06-1621:50:47
www.ibm.com
11

0.947 High

EPSS

Percentile

99.3%

Summary

A vulnerability in OpenLDAP affects IBM Security Access Manager appliances.

Vulnerability Details

CVEID: CVE-2015-6908**
DESCRIPTION:** OpenLDAP is vulnerable to a denial of service, caused by an assertion error in the ber_get_next() function. By sending a specially-crafted packet, a remote attacker could exploit this vulnerability to cause the slapd service to crash.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/106296&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM Security Access Manager for Web 7.0 appliances, all firmware versions.

IBM Security Access Manager for Web 8.0 appliances, all firmware versions.

IBM Security Access Manager for Mobile 8.0 appliances, all firmware versions.

IBM Security Access Manager 9.0 appliances, all firmware versions.

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager for Web 7.0 (appliance) N/A Apply Interim Fix 29:
7.0.0-ISS-WGA-IF0029
IBM Security Access Manager for Web 8.0.0.0 -
8.0.1.5 IV93443 1. For versions prior to 8.0.1.5, upgrade to 8.0.1.5:
8.0.1-ISS-WGA-FP0005
2. Upgrade to 8.0.1.5 IF 1:
8.0.1.5-ISS-WGA-IF0001
IBM Security Access Manager for Mobile 8.0.0.0 -
8.0.1.5 IV93445 1. For versions prior to 8.0.1.5, upgrade to 8.0.1.5:
8.0.1-ISS-ISAM-FP0005
2. Upgrade to 8.0.1.5 IF 1:
8.0.1.5-ISS-ISAM-IF0001
IBM Security Access Manager 9.0 -
9.0.2.0 IV92196 1. For versions prior to 9.0.2.1, upgrade to 9.0.2.1:
9.0.2-ISS-ISAM-FP0001

Workarounds and Mitigations

None.