cbcvebase.
CVE-2008-7289
published 2011-04-21

CVE-2008-7289: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it…

medium4CVSS 3.1
AVNACLAuSCNINAP
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmtivoli_directory_server
ibmtivoli_directory_server