APP: IBM Director CIM Server Consumer Name Handling Denial of Service

This signature detects attempts to exploit a known vulnerability in the CIM Server of IBM Director. The vulnerability is due to errors when processing certain types of requests. A remote attacker can exploit this vulnerability by sending crafted requests to the target host. Successful exploitation would be a denial of service (DoS) condition of System Director services on the target host. In a successful attack case, the affected server will terminate and will not be available until the service is manually restarted.

Extended Description

The CIM Server of IBM Director is prone to a remote denial-of-service vulnerability because the application fails to properly handle specially crafted requests. Successfully exploiting this issue allows remote attackers to trigger crashes, which would deny further service to legitimate users. This issue affects versions prior to IBM Director 5.20.3 Service Update 2.

Affected Products

Ibm director

References

BugTraq: 34061

CVE: CVE-2009-0879

Short Name
APP:IBM:DIRECTOR-CIM-DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CIM CVE-2009-0879 Consumer Denial Director Handling IBM Name Server Service bid:34061 of
Release Date
07/21/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/6988
False Positive
Unknown
Vendors

Ibm

CVSS Score

5.0

Found a potential security threat?