Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

DB:IBM-SOLIDDB-AUTH-BYPASS

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

IBM solidDB solid.exe Authentication Bypass

Release Date

2011/06/20

Update Number

1942

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

DB: IBM solidDB solid.exe Authentication Bypass


This signature detects attempts to exploit a known authentication bypass vulnerability in IBM solidDB. A remote unauthenticated attacker could exploit this vulnerability by specifying a small password hash length value and fuzzing the password hash. Successful exploitation may allow the attacker to bypass authentication to the database.

Extended Description

IBM solidDB is prone to a remote authentication-bypass vulnerability that affects the 'solid.exe' process. Successfully exploiting this issue will allow remote attackers to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers.

Affected Products

  • Ibm soliddb 4.5.167
  • Ibm soliddb 4.5.168
  • Ibm soliddb 4.5.169
  • Ibm soliddb 4.5.173
  • Ibm soliddb 4.5.175
  • Ibm soliddb 4.5.176
  • Ibm soliddb 4.5.178
  • Ibm soliddb 4.5.180
  • Ibm soliddb 6.0.1060
  • Ibm soliddb 6.0.1061
  • Ibm soliddb 6.0.1064
  • Ibm soliddb 6.0.1065
  • Ibm soliddb 6.0.1066
  • Ibm soliddb 6.1
  • Ibm soliddb 6.1.20
  • Ibm soliddb 6.30.0039
  • Ibm soliddb 6.30.0040
  • Ibm soliddb 6.30.0044
  • Ibm soliddb 6.30.0.29
  • Ibm soliddb 6.30.0.33
  • Ibm soliddb 6.30.0.37
  • Ibm soliddb 6.3.33
  • Ibm soliddb 6.3.37
  • Ibm soliddb 6.3 FP 6
  • Ibm soliddb 6.5
  • Ibm soliddb 6.5.0.0
  • Ibm soliddb 6.5.0.1
  • Ibm soliddb 6.5.0.2
  • Ibm soliddb 6.5.0.3
  • Ibm soliddb 6.5 FP 2

References

  • BugTraq: 47137

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out