Lucene search

K
kasperskyKaspersky LabKLA10503
HistoryMar 24, 2015 - 12:00 a.m.

KLA10503 Multiple vulnerabilities in IBM products

2015-03-2400:00:00
Kaspersky Lab
threats.kaspersky.com
44

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

AI Score

5.7

Confidence

Low

EPSS

0.005

Percentile

76.0%

Multiple serious vulnerabilities have been found in IBM products.

Below is a complete list of vulnerabilities

  1. Improper WAR applications support in IBM Bluemix can be exploited remotely via unspecified vectors related to Java overlay feature;
  2. Improper API access restrictions in IBM API management can be exploited remotely via a specially designed API calls;
  3. Improper TLS state translation in ITDS and ISDS can be exploited remotely via a specially designed TLS traffic;
  4. Improper query handling in IBM Content Collector can be exploited remotely via a specially designed query;
  5. Improper trace and log realization in IBM TIMAD and SIMAD can be exploited locally via log reading;
  6. Lack of password handling restrictions in IBM RAtional ClearCase can be exploited locally via mani0pulations with installation account.

Original advisories

Related products

IBM-Tivoli-Directory-Server

IBM-Content-Collector-for-Email

IBM-Bluemix

CVE list

CVE-2014-8923 warning

CVE-2015-0138 warning

CVE-2015-0149 high

CVE-2015-0146 warning

CVE-2014-6134 warning

CVE-2015-0178 warning

Solution

Update to latest version

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

Affected Products

  • IBM Bluemix Liberty versions earlier than 1.13-20150209-1122IBM API Management 3 versions earlier 3.0.4.1IBM Content Collector for Email 3 versions earlier than 3.0.0.6-IBM-ICC-Server-IF001IBM Content Collector for Email 4 before 4.0.0.3-IBM-ICC-Server-IF001 IBM Tivoli Directory Server (ITDS) 6 versions earlier than 6.0.0.73-ISS-ITDS-IF0073IBM Tivoli Directory Server (ITDS) 6.1 versions earlier than 6.1.0.66-ISS-ITDS-IF0066IBM Tivoli Directory Server (ITDS) 6.2 versions earlier than 6.2.0.42-ISS-ITDS-IF0042IBM Tivoli Directory Server (ITDS) 6.3 versions earlier than 6.3.0.35-ISS-ITDS-IF0035IBM Security Directory Server (ISDS) 6.3.1 versions earlier than 6.3.1.9-ISS-ISDS-IF0009IBM Tivoli Identity Manager Active Directory adapter versions earlier than 5.1.4IBM Security Identity Manager Active Directory adapter versions earlier than 6.0.14IBM Rational ClearCase 8.0.0 before 8.0.0.14IBM Rational ClearCase 8.0.1 before 8.0.1.7

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

AI Score

5.7

Confidence

Low

EPSS

0.005

Percentile

76.0%