- Description
- IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:global_security_kit:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDD46A9C-9DB2-4B61-BCEA-DC5AB03DCD7E",
"versionEndIncluding": "8.0.13"
},
{
"criteria": "cpe:2.3:a:ibm:global_security_kit:7.0.4.28:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2FD561AD-2421-4AA6-B3C5-6536F6933526"
},
{
"criteria": "cpe:2.3:a:ibm:global_security_kit:7.0.4.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00E509BA-4B47-4EDE-86DC-2E666D2D74E0"
},
{
"criteria": "cpe:2.3:a:ibm:rational_directory_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0651DE7C-B8EB-4214-981B-561256C5473A"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_directory_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "871E249E-CB31-46A4-9E4F-274C6055C33A"
}
],
"operator": "OR"
}
]
}
]