IBM Multiple Products Global Security Toolkit Security Vulnerabilities
BID:54743
Info
IBM Multiple Products Global Security Toolkit Security Vulnerabilities
| Bugtraq ID: | 54743 |
| Class: | Design Error |
| CVE: |
CVE-2012-2203 CVE-2012-2191 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2012 12:00AM |
| Updated: | Mar 19 2015 09:05AM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere MQ 7.0.1.0 IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .13 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 41 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.6 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.4 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1.0.43 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.37 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Tivoli Netcool/OMNIbus 7.3 IBM Tivoli Monitoring 6.2.3 IBM Tivoli Monitoring 6.2.2 IBM Tivoli Monitoring 6.2.1 IBM Tivoli Monitoring 6.2 IBM Tivoli Directory Server 6.3 IBM Tivoli Directory Server 6.2 IBM Tivoli Directory Server 6.1 IBM Tivoli Directory Server 6.0 IBM Tivoli Access Manager for e-business 6.1 IBM Tivoli Access Manager for e-business 6.0 .17 IBM Tivoli Access Manager for e-business 6.0 IBM Tivoli Access Manager for e-business 6.1.0.5 IBM Tivoli Access Manager for e-business 6.1.0 IBM Tivoli Access Manager for e-business 6.0.0.25 IBM IBM Rational ClearQuest 7.1.1 IBM IBM Rational ClearQuest 8.0.0.2 IBM IBM Rational ClearQuest 8.0.0.1 IBM IBM Rational ClearQuest 7.1.2.6 IBM IBM Rational ClearQuest 7.1.2.5 IBM IBM Rational ClearQuest 7.1.1.9 IBM DB2 Workgroup Server Edition 9.7 IBM DB2 Workgroup Server Edition 9.5 IBM DB2 Express Edition 9.7 IBM DB2 Express Edition 9.5 IBM DB2 Enterprise Server Edition 9.5 IBM DB2 Connect Unlimited Edition for System z 9.7 IBM DB2 Connect Unlimited Edition for System z 9.5 IBM DB2 Connect Unlimited Edition for System i 9.7 IBM DB2 Connect Unlimited Edition for System i 9.5 IBM DB2 Connect Enterprise Edition 9.7 IBM DB2 Connect Enterprise Edition 9.5 IBM DB2 Advanced Enterprise Server Edition 9.7 IBM DB2 Advanced Enterprise Server Edition 9.5 IBM Application Manager for Smart Business 1.2.1 |
| Not Vulnerable: |
IBM Websphere Application Server 6.1.0.45 |
Discussion
IBM Multiple Products Global Security Toolkit Security Vulnerabilities
IBM Multiple Products are prone to multiple security vulnerabilities.
Successful exploits may allow an attacker to crash the affected application or spoof a valid server and conduct man-in-the-middle attacks.
Note: This issue was previously titled 'IBM Rational Directory Server Multiple Security Vulnerabilities'. The title and technical details have been changed to better reflect the underlying component affected.
IBM Multiple Products are prone to multiple security vulnerabilities.
Successful exploits may allow an attacker to crash the affected application or spoof a valid server and conduct man-in-the-middle attacks.
Note: This issue was previously titled 'IBM Rational Directory Server Multiple Security Vulnerabilities'. The title and technical details have been changed to better reflect the underlying component affected.
Exploit / POC
IBM Multiple Products Global Security Toolkit Security Vulnerabilities
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
IBM Multiple Products Global Security Toolkit Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM Multiple Products Global Security Toolkit Security Vulnerabilities
References:
References:
- IBM Homepage (IBM)