First published: Tue Jul 03 2007(Updated: )
IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM iSeries AS/400 | =r520 | |
IBM iSeries AS/400 | =v4r2m0 | |
IBM iSeries AS/400 | =v4r3 | |
IBM iSeries AS/400 | =v4r4 | |
IBM iSeries AS/400 | =v4r5 | |
IBM iSeries AS/400 | =v5r1 | |
IBM iSeries AS/400 | =v5r2m0 | |
IBM iSeries AS/400 | =v5r3m0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3537 is classified as a medium severity vulnerability due to its potential to expose sensitive system information.
To mitigate CVE-2007-3537, ensure that your IBM OS/400 system is updated to a version that does not respond to TCP SYN-FIN packets.
CVE-2007-3537 affects IBM OS/400 versions from V4R2M0 through V5R3M0.
Yes, CVE-2007-3537 can be exploited by remote attackers to retrieve system information.
If you are using an affected version, it is recommended to upgrade to a patched version or apply network security measures to block unauthorized access.