IBM Director CIM Server Consumer Name Remote Denial of Service Vulnerability
BID:34061
Info
IBM Director CIM Server Consumer Name Remote Denial of Service Vulnerability
| Bugtraq ID: | 34061 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-0879 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2009 12:00AM |
| Updated: | Mar 20 2009 08:06PM |
| Credit: | Bernhard Mueller |
| Vulnerable: |
IBM Director 5.20.3 IBM Director 5.20.1 |
| Not Vulnerable: |
IBM Director 5.20.3 Service Update 2 |
Discussion
IBM Director CIM Server Consumer Name Remote Denial of Service Vulnerability
The CIM Server of IBM Director is prone to a remote denial-of-service vulnerability because the application fails to properly handle specially crafted requests.
Successfully exploiting this issue allows remote attackers to trigger crashes, which would deny further service to legitimate users.
This issue affects versions prior to IBM Director 5.20.3 Service Update 2.
The CIM Server of IBM Director is prone to a remote denial-of-service vulnerability because the application fails to properly handle specially crafted requests.
Successfully exploiting this issue allows remote attackers to trigger crashes, which would deny further service to legitimate users.
This issue affects versions prior to IBM Director 5.20.3 Service Update 2.
Exploit / POC
IBM Director CIM Server Consumer Name Remote Denial of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
Attackers can use readily available network utilities to exploit this issue.
Solution / Fix
IBM Director CIM Server Consumer Name Remote Denial of Service Vulnerability
Solution:
Reports indicate that IBM released Director 5.20.3 Service Update 2 to address this issue. Symantec was unable to verify this information. Please see the references and contact the vendor for more information.
Solution:
Reports indicate that IBM released Director 5.20.3 Service Update 2 to address this issue. Symantec was unable to verify this information. Please see the references and contact the vendor for more information.
References
IBM Director CIM Server Consumer Name Remote Denial of Service Vulnerability
References:
References:
- IBM Director Homepage (IBM)
- SEC-CONSULT Security Advisory < 20090305-1 > (SEC-CONSULT)
- SEC Consult SA-20090305-1 :: IBM Director CIM Server Remote Denial of Service Vu (Bernhard Mueller
)