vendor:
IBM Director
by:
Bernhard Mueller / SEC Consult Vulnerability Lab
7.5
CVSS
HIGH
Remote Denial of Service
N/A
CWE
Product Name: IBM Director
Affected Version From: <= 5.20.3 Service Update 1
Affected Version To: <= 5.20.3 Service Update 2
Patch Exists: YES
Related CWE: N/A
CPE: IBM Director for Windows
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
IBM Director CIM Server Remote Denial of Service Vulnerability
The CIM server contained in the IBM Director suite for Microsoft Windows is vulnerable to a remote denial of service attack. The vulnerability allows an attacker to crash the service remotely. It will not be possible to reach the IBM Director agent until the service is manually restarted. CIM server crashes on receiving requests that contain overlong consumer names. The error condition does not allow for the redirection of program flow.
Mitigation:
The vendor has adressed this vulnerability in service update 2 for IBM Director agent 5.20.3.