CVE-2015-5012
Summary
| CVE | CVE-2015-5012 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-02-15 02:59:00 UTC |
| Updated | 2016-03-11 15:23:00 UTC |
| Description | The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. |
Risk And Classification
Problem Types: CWE-310
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| Security Bulletin: IBM Security Access Manager for Web appliances has some weak SSH MAC Algorithms enabled (CVE-2015-5012) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.