SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#512193

IBM Director fails to properly time-out connection requests from clients

Overview

IBM Director Systems, specifically CIM Server, contains a denial-of-service vulnerability that can allow a remote, unauthenticated attacker to render Director inoperative.

I. Description

IBM Director is a suite of system management tools.

When a rogue connection request is made to IBM Director Systems, specifically the CIM Server, a thread is created that listens on a port, waiting for a specific response from the client. If the client does not send the expected response, the thread remains in memory listening, indicating a high CPU utilization until the client connects to it. If multiple rogue clients connect simultaneously, the finite number of connections can be exhausted causing server to crash.

Versions 5.20.1 and earlier for Windows and Linux are affected.

II. Impact

IBM Director Systems will become inaccessible for management.

III. Solution

Apply an update


Download and Apply the patch for Windows and Linux systems here:
https://www14.software.ibm.com/webapp/iwm/web/preLogin.do?source=dmp

Block or restrict access

Employ other protection mechanisms that will restrict access to the Director Systems by installing firewalls, defining filters, or by using reverse proxies.

Systems Affected

VendorStatusDate NotifiedDate Updated
IBM eServerVulnerable20-Nov-2007

References


https://www14.software.ibm.com/webapp/iwm/web/preLogin.do?source=dmp
http://www-03.ibm.com/systems/management/director/

Credit

Thanks to IBM for reporting this vulnerability, who in turn credit Juniper Networks.

This document was written by Will Dormann.

Other Information

Date Public:2007-11-20
Date First Published:2007-11-20
Date Last Updated:2007-11-20
CERT Advisory: 
CVE-ID(s):CVE-2007-5612
NVD-ID(s):CVE-2007-5612
US-CERT Technical Alerts: 
Metric:0.91
Document Revision:5

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader