CVE-2012-0726: Medium severity ibm tivoli directory server vulnerability
The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0726?
CVE-2012-0726 has a moderate severity rating due to its potential for enabling unencrypted communications.
How do I fix CVE-2012-0726?
To mitigate CVE-2012-0726, configure IBM Tivoli Directory Server to disable the NULL-MD5 and NULL-SHA cipher suites.
What systems are affected by CVE-2012-0726?
CVE-2012-0726 affects multiple versions of IBM Tivoli Directory Server including versions from 3.2.2 to 6.3.0.
What are the risks associated with CVE-2012-0726?
The risks associated with CVE-2012-0726 include unauthorized access to sensitive information due to unencrypted TLS communications.
Is there a patch for CVE-2012-0726?
IBM has released guidance on securing the affected versions, but specific patches may vary based on the installed version of Tivoli Directory Server.