CVE-2015-1892
Summary
| CVE | CVE-2015-1892 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-04-01 02:00:32 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ibm | Security Access Manager For Web 7.0 Firmware | All | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.1 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.2 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.3 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.4 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.5 | All | All | All |
| Operating System | Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM Security Bulletin: mDNS vulnerability affects IBM Security Access Manager for Web (CVE-2015-1892) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| Multiple Products Multicast DNS (mDNS) Implementation Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Vulnerability Note VU#550620 - Multicast DNS (mDNS) implementations may respond to unicast queries originating outside the local link | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.