IBM Tivoli Directory Server 6.1.0.72

CPE Details

IBM Tivoli Directory Server 6.1.0.72
6.1.0.72
2019-12-16
12h48 +00:00
2019-12-16
12h48 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ibm:tivoli_directory_server:6.1.0.72:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

tivoli_directory_server

Version

6.1.0.72

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2015-1976 2017-02-08 21h00 +00:00 IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
5.5
Moyen
CVE-2015-1977 2016-07-15 16h00 +00:00 Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before 6.3.1.18-ISS-ISDS-IF0018 and 6.4.x before 6.4.0.9-ISS-ISDS-IF0009 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
7.5
Haute
CVE-2012-2191 2012-08-08 08h00 +00:00 IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, does not properly validate data during execution of a protection mechanism against the Vaudenay SSL CBC timing attack, which allows remote attackers to cause a denial of service (application crash) via crafted values in the TLS Record Layer, a different vulnerability than CVE-2012-2333.
5
CVE-2012-2203 2012-08-08 08h00 +00:00 IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects without enforcing file integrity, which makes it easier for remote attackers to spoof SSL servers via vectors involving insertion of an arbitrary root Certification Authority (CA) certificate.
7.5
CVE-2012-0726 2012-04-22 16h00 +00:00 The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.
6.4
CVE-2012-0743 2012-04-22 16h00 +00:00 IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request.
5