Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:IBM-SOLIDDB-AUTH-BYPASS

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

IBM solidDB solid.exe Authentication Bypass

Release Date

2011/06/20

Update Number

1942

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: IBM solidDB solid.exe Authentication Bypass


This signature detects attempts to exploit a known authentication bypass vulnerability in IBM solidDB. A remote unauthenticated attacker could exploit this vulnerability by specifying a small password hash length value and fuzzing the password hash. Successful exploitation may allow the attacker to bypass authentication to the database.

Extended Description

IBM solidDB is prone to a remote authentication-bypass vulnerability that affects the 'solid.exe' process. Successfully exploiting this issue will allow remote attackers to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers.

Affected Products

  • IBM solidDB 4.5.167
  • IBM solidDB 4.5.168
  • IBM solidDB 4.5.169
  • IBM solidDB 4.5.173
  • IBM solidDB 4.5.175
  • IBM solidDB 4.5.176
  • IBM solidDB 4.5.178
  • IBM solidDB 4.5.180
  • IBM solidDB 6.0.1060
  • IBM solidDB 6.0.1061
  • IBM solidDB 6.0.1064
  • IBM solidDB 6.0.1065
  • IBM solidDB 6.0.1066
  • IBM solidDB 6.1
  • IBM solidDB 6.1.20
  • IBM solidDB 6.30.0039
  • IBM solidDB 6.30.0040
  • IBM solidDB 6.30.0044
  • IBM solidDB 6.30.0.29
  • IBM solidDB 6.30.0.33
  • IBM solidDB 6.30.0.37
  • IBM solidDB 6.3.33
  • IBM solidDB 6.3.37
  • IBM solidDB 6.3 FP 6
  • IBM solidDB 6.5
  • IBM solidDB 6.5.0.0
  • IBM solidDB 6.5.0.1
  • IBM solidDB 6.5.0.2
  • IBM solidDB 6.5.0.3
  • IBM solidDB 6.5 FP 2

References

  • BugTraq: 47137

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out