CVE-2015-1892
Summary
| CVE | CVE-2015-1892 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-01 02:00:00 UTC |
| Updated | 2016-08-04 03:25:00 UTC |
| Description | The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Products Multicast DNS (mDNS) Implementation Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| IBM Security Bulletin: mDNS vulnerability affects IBM Security Access Manager for Web (CVE-2015-1892) - United States | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| Vulnerability Note VU#550620 - Multicast DNS (mDNS) implementations may respond to unicast queries originating outside the local link | CERT-VN | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.