IBM Corporation Information for VU#194753

IBM Tivoli Directory Server may allow unauthorized access



Vendor Statement

A potential security vulnerability has been identified by IBM for the
IBM Tivoli Directory Server (ITDS), version 5.2.0 and 6.0.0.

This information has been updated as of November 7th, 2005

IBM has identified a vulnerability that would allow unauthorized access
to change, modify and/or delete directory data stored in IBM Tivoli
Directory Server. While it is not believed that this vulnerability
exists when the IBM Tivoli Directory Server is set to use SSL only and
SSL Client Server authentication, IBM strongly recommends that all
customers update their installation with the correct fix.

Customers are strongly recommended to apply the appropriate fix as soon
as possible.

Please refer to the following link for more information:

For any questions, support can be obtained through the following means:
? Local call center - A list of country-specific phone numbers can be
found at:
? Create PMR through the online support page:

Please refer to
for information regarding these options.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



Please reference the IBM Security Vulnerability note on this issue for information on updates, fixes, and workarounds.

If you have feedback, comments, or additional information about this vulnerability, please send us email.