First published: Mon Feb 15 2016(Updated: )
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager 9.0 | =9.0.0 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.1 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.2 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.3 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.4 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.5 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.6 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.7 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.8 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.9 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.10 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.11 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.12 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.13 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.14 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.15 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.16 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.17 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.18 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.1 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.2 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.3 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.5 | |
IBM Security Access Manager for Web 8.0 | =8.0.1 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.0 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5012 has a medium severity rating due to its potential to allow attackers to bypass cryptographic protections.
To fix CVE-2015-5012, upgrade to IBM Security Access Manager for Web version 7.0.0 FP19, 8.0.1.3 IF3, or 9.0.0.0 IF1 or later.
CVE-2015-5012 can be exploited by attackers to weaken SSH connections and compromise data confidentiality.
CVE-2015-5012 affects IBM Security Access Manager for Web versions 7.0, 8.0, and 9.0 prior to their respective fixed versions.
There are no documented workarounds for CVE-2015-5012; the recommended solution is to apply the relevant updates.