CVE-2005-3567IBM Tivoli Directory Server vulnerability

CWE-2643 documents3 sources
Severity
5.8MEDIUMNVD
EPSS
0.9%
top 24.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 16
Latest updateMay 1

Description

slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.

CVSS vector

AV:A/AC:L/C:P/I:P/A:PExploitability: 6.5 | Impact: 6.4

Affected Packages1 packages

NVDibm/tivoli_directory_server5.2.0, 6.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pgj4-m7wx-hrhh: slapd daemon in IBM Tivoli Directory Server (ITDS) 52022-05-01
CVEList
CVE-2005-3567: slapd daemon in IBM Tivoli Directory Server (ITDS) 52005-11-16
CVE-2005-3567 — IBM vulnerability | cvebase