IBM solidDB Password Hash Length Remote Authentication Bypass Vulnerability
BID:47137
Info
IBM solidDB Password Hash Length Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 47137 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2011 12:00AM |
| Updated: | Apr 01 2011 12:00AM |
| Credit: | Tenable Network Security via the Zero Day Initiative |
| Vulnerable: |
IBM solidDB 6.5.0.3 IBM solidDB 6.5 FP 2 IBM solidDB 6.5 IBM solidDB 6.30.0.37 IBM solidDB 6.30.0.33 IBM solidDB 6.30.0.29 IBM solidDB 6.3 FP 6 IBM solidDB 4.5.180 |
| Not Vulnerable: | |
Discussion
IBM solidDB Password Hash Length Remote Authentication Bypass Vulnerability
IBM solidDB is prone to a remote authentication-bypass vulnerability that affects the 'solid.exe' process.
Successfully exploiting this issue will allow remote attackers to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers.
IBM solidDB is prone to a remote authentication-bypass vulnerability that affects the 'solid.exe' process.
Successfully exploiting this issue will allow remote attackers to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers.
Exploit / POC
IBM solidDB Password Hash Length Remote Authentication Bypass Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
IBM solidDB Password Hash Length Remote Authentication Bypass Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
IBM solidDB Password Hash Length Remote Authentication Bypass Vulnerability
References:
References:
- solidDB Homepage (IBM)
- ZDI-11-115: IBM solidDB solid.exe Authentication Bypass Remote Code Execution V (ZDI Disclosures
) - Security Alert: Vulnerability in IBM solidDB allows bypassing of user authentica (IBM)
- ZDI-11-115 IBM solidDB solid.exe Authentication Bypass Remote Code Execution Vul (Zero Day Initiative)