First published: Wed Feb 08 2017(Updated: )
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Directory Server | >=6.3.0.0<=6.3.1.15 | |
IBM Security Directory Server | >=6.4.0.0<=6.4.0.6 | |
IBM Tivoli Directory Server | >=6.0<=6.0.0.77 | |
IBM Tivoli Directory Server | >=6.1.0<=6.1.0.72 | |
IBM Tivoli Directory Server | >=6.2.0.0<=6.2.0.48 | |
IBM Tivoli Directory Server | >=6.3.0.0<=6.3.0.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1976 is rated as important due to its potential to allow command execution and crashes in the web administration tool.
To fix CVE-2015-1976, upgrade IBM Security Directory Server or IBM Tivoli Directory Server to the latest versions beyond the specified vulnerable versions.
CVE-2015-1976 is caused by improper handling of user input in the web administration tool, allowing authenticated users to execute harmful commands.
CVE-2015-1976 affects versions of IBM Security Directory Server and IBM Tivoli Directory Server up to certain fixed versions specified by IBM.
The implications of CVE-2015-1976 include potential service disruption and unauthorized command execution that could affect server operations.