PT-2011-1282 · Ibm · Ibm Tivoli Directory Server+1

Published

2011-04-21

·

Updated

2011-04-21

·

CVE-2008-7289

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM Tivoli Directory Server (TDS) versions prior to 5.2.0.5-TIV-ITDS-LA0007
Description The issue arises from improper handling of simultaneous password changes, which can lead to a denial of service due to a DB2 daemon deadlock. This occurs when password changes trigger updates to a DB2 password-history table.
Recommendations For versions prior to 5.2.0.5-TIV-ITDS-LA0007, update to version 5.2.0.5-TIV-ITDS-LA0007 or later to resolve the issue. As a temporary workaround, consider restricting simultaneous password changes to minimize the risk of triggering the DB2 daemon deadlock.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7289

Affected Products

Db2
Ibm Tivoli Directory Server