Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
IBM solidDB User Authentication Bypass Vulnerability
Information
Severity
Severity
Critical
Family
Family
Denial of Service
CVSSv2 Base
CVSSv2 Base
9.3
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Solution Type
Solution Type
Vendor Patch
Created
Created
12 years ago
Modified
Modified
5 years ago
Summary
This host is running IBM solidDB and is prone to authentication bypass vulnerability.
Insight
Insight
The flaw exists within the 'solid.exe' process which listens by default on TCP ports 1315, 1964 and 2315. The authentication protocol allows a remote attacker to specify the length of a password hash. An attacker could bypass the authentication by specifying short length value.
Affected Software
Affected Software
IBM solidDB version before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3
Solution
Solution
Apply the patches from the referenced advisory.