IBM Director CIM Server Remote Denial of Service Vulnerability
BID:26509
Info
IBM Director CIM Server Remote Denial of Service Vulnerability
| Bugtraq ID: | 26509 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-5612 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2007 12:00AM |
| Updated: | Nov 21 2007 12:34AM |
| Credit: | IBM credits Juniper Networks with the discovery of this issue. |
| Vulnerable: |
IBM Director 5.20.1 IBM Director 5.10.3 IBM Director 3.1 IBM Director 5.10 IBM Director 0 |
| Not Vulnerable: | |
Discussion
IBM Director CIM Server Remote Denial of Service Vulnerability
The CIM Server from the IBM Director suite is prone to a remote denial-of-service vulnerability because the application fails to properly handle multiple simultaneous network connections.
Successfully exploiting this issue allows remote attackers to consume excessive CPU resources and to trigger crashes, which would deny further service to legitimate users.
IBM Director 5.20.1 and prior versions on Linux and Microsoft Windows platforms are affected.
The CIM Server from the IBM Director suite is prone to a remote denial-of-service vulnerability because the application fails to properly handle multiple simultaneous network connections.
Successfully exploiting this issue allows remote attackers to consume excessive CPU resources and to trigger crashes, which would deny further service to legitimate users.
IBM Director 5.20.1 and prior versions on Linux and Microsoft Windows platforms are affected.
Exploit / POC
IBM Director CIM Server Remote Denial of Service Vulnerability
Attackers use readily available network utilities to exploit this issue.
Attackers use readily available network utilities to exploit this issue.
Solution / Fix
IBM Director CIM Server Remote Denial of Service Vulnerability
Solution:
IBM has released fixes to address this issue. Please see the references for more information.
Solution:
IBM has released fixes to address this issue. Please see the references for more information.
References
IBM Director CIM Server Remote Denial of Service Vulnerability
References:
References:
- IBM Director Homepage (IBM)
- IBM Director Patch Download (IBM)
- Vulnerability Note VU#512193 (US-CERT)