Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:IBM:DIRECTOR-CIM-DOS

Severity

High

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

IBM Director CIM Server Consumer Name Handling Denial of Service

Release Date

2011/07/20

Update Number

1959

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: IBM Director CIM Server Consumer Name Handling Denial of Service


This signature detects attempts to exploit a known vulnerability in the CIM Server of IBM Director. The vulnerability is due to errors when processing certain types of requests. A remote attacker can exploit this vulnerability by sending crafted requests to the target host. Successful exploitation would be a denial of service (DoS) condition of System Director services on the target host. In a successful attack case, the affected server will terminate and will not be available until the service is manually restarted.

Extended Description

The CIM Server of IBM Director is prone to a remote denial-of-service vulnerability because the application fails to properly handle specially crafted requests. Successfully exploiting this issue allows remote attackers to trigger crashes, which would deny further service to legitimate users. This issue affects versions prior to IBM Director 5.20.3 Service Update 2.

Affected Products

  • IBM Director 5.20.1
  • IBM Director 5.20.3

References

  • BugTraq: 34061
  • CVE: CVE-2009-0879

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out