search menu icon-carat-right cmu-wordmark

CERT Coordination Center

IBM Tivoli Directory Server may allow unauthorized access

Vulnerability Note VU#194753

Original Release Date: 2005-11-17 | Last Revised: 2005-12-08

Overview

IBM Tivoli Directory Server may allow unauthorized access to change, modify, and/or delete directory data under certain circumstances.

Description

The IBM Tivoli Directory Server product is described as:

IBM Tivoli Directory Server provides a powerful Lightweight Directory Access Protocol (LDAP) identity infrastructure that is the foundation for deploying comprehensive identity management applications and advanced software architectures like Web services.

The Tivoli Directory Server may allow unauthorized access enabling attackers to manipulate directory data that they should not be able to access or change. Additional details about the underlying cause of the vulnerability are not available.

Impact

An attacker may be able to access, delete, modify, or change directory data.

Solution

Apply an update
Please reference the IBM Security Vulnerability note on this issue for information on updates, fixes, and workarounds.


Use SSL communication and authentication

Enabling SSL-only communication and SSL Client-Server authentication is believed to mitigate the flaw being exposed, although all customers are urged to apply the updates.

Vendor Information

194753
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to IBM for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

CVE IDs: None
Severity Metric: 17.93
Date Public: 2005-11-09
Date First Published: 2005-11-17
Date Last Updated: 2005-12-08 15:33 UTC
Document Revision: 10

Sponsored by CISA.