Ibm Tivoli Directory Server vulnerabilities
43 known vulnerabilities affecting ibm/tivoli_directory_server.
Total CVEs
43
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM34LOW4
Vulnerabilities
Page 1 of 3
CVE-2011-1206P2CRITICALCVSS 10.0PoCv5.2.0v5.2.0.4+82 more2011-04-21
CVE-2011-1206 [CRITICAL] CWE-119 CVE-2011-1206: Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TD
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) allows
nvd
CVE-2004-2526P4MEDIUMCVSS 5.0PoC≤ 4.1v3.2.22004-12-31
CVE-2004-2526 [MEDIUM] CVE-2004-2526: Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allow
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.
nvd
CVE-2008-2943P4MEDIUMCVSS 6.0PoCv6.1.0.0v6.1.0.1+14 more2008-06-30
CVE-2008-2943 [MEDIUM] CWE-399 CVE-2008-2943: Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remot
Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulne
nvd
CVE-2006-0717P4MEDIUMCVSS 5.0PoCv6.02006-02-15
CVE-2006-0717 [MEDIUM] CVE-2006-0717: IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a c
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
nvd
CVE-2015-1977P3HIGHCVSS 7.5v6.2.0v6.2.0.0+160 more2016-07-15
CVE-2015-1977 [HIGH] CWE-200 CVE-2015-1977: Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITD
Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before 6.2.0.50-ISS-ISDS-IF0050, and 6.3.x before 6.3.0.43-ISS-ISDS-IF0043 and IBM Security Directory Server (ISDS) before 6.3.1.18-ISS-ISDS-IF0018 and 6.4.x before 6.4.0.9-ISS-ISDS-IF0009 allows remote attackers
nvd
CVE-2015-1975P3HIGHCVSS 7.8v6.0v6.1.0+4 more2018-04-03
CVE-2015-1975 [HIGH] CWE-74 CVE-2015-1975: The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before i
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694.
nvd
CVE-2009-3088P4HIGHCVSS 7.5v6.02009-09-08
CVE-2009-3088 [HIGH] CWE-119 CVE-2009-3088: Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows rem
Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via unknown vectors that trigger heap corruption, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because th
nvd
CVE-2015-1974P4MEDIUMCVSS 6.5v6.0v6.1.0+4 more2015-06-28
CVE-2015-1974 [MEDIUM] CWE-264 CVE-2015-1974: The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before i
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote authenticated users to bypass intended command restrictions via unspecified vectors.
nvd
CVE-2012-0726P4MEDIUMCVSS 6.4≤ 6.3.0v3.2.2+17 more2012-04-22
CVE-2012-0726 [MEDIUM] CWE-310 CVE-2012-0726: The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (
The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger unencrypted communication via the TLS Handshake Protocol.
nvd
CVE-2009-3089P4HIGHCVSS 7.8v6.02009-09-08
CVE-2009-3089 [HIGH] CVE-2009-3089: IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL poi
IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors, related to (1) the ibmslapd.exe daemon on Windows and (2) the ibmdiradm daemon in the administration server on Linux, as demonstrated by certain modules in VulnDisco Pack Professional 8.11, a different v
nvd
CVE-2011-2758P4MEDIUMCVSS 5.0v6.2v6.2.0.0+2 more2011-07-17
CVE-2011-2758 [MEDIUM] CWE-287 CVE-2011-2758: IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV
IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for access to LDAP Server log files, which allows remote attackers to obtain sensitive information via a crafted URL.
nvd
CVE-2015-0138P4MEDIUMCVSS 4.3≤ 6.0.0.73v6.1.0+138 more2015-03-25
CVE-2015-0138 [MEDIUM] CWE-310 CVE-2015-0138: GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66
GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remo
nvd
CVE-2011-2759P4MEDIUMCVSS 5.0v6.2v6.2.0.0+2 more2011-07-17
CVE-2011-2759 [MEDIUM] CWE-200 CVE-2011-2759: The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2
The login page of IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
nvd
CVE-2007-6742P4MEDIUMCVSS 6.8v5.2.0v5.2.0.42011-04-21
CVE-2007-6742 [MEDIUM] CWE-399 CVE-2007-6742: The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006
The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.
nvd
CVE-2015-1976P4MEDIUMCVSS 5.5≥ 6.0, ≤ 6.0.0.77≥ 6.1.0, ≤ 6.1.0.72+2 more2017-02-08
CVE-2015-1976 [MEDIUM] CWE-284 CVE-2015-1976: IBM Security Directory Server could allow an authenticated user to execute commands into the web adm
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
nvd
CVE-2010-4217P4MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+22 more2010-11-09
CVE-2010-4217 [MEDIUM] CWE-399 CVE-2010-4217: Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before
Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.
nvd
CVE-2012-0743P4MEDIUMCVSS 5.0≤ 6.3.0v3.2.2+17 more2012-04-22
CVE-2012-0743 [MEDIUM] CWE-399 CVE-2012-0743: IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of servi
IBM Tivoli Directory Server (TDS) 6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via a malformed LDAP paged search request.
nvd
CVE-2005-3567P4MEDIUMCVSS 5.8v5.2.0v6.02005-11-16
CVE-2005-3567 [MEDIUM] CWE-264 CVE-2005-3567: slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.
nvd
CVE-2010-0312P4MEDIUMCVSS 5.0v6.22010-01-14
CVE-2010-0312 [MEDIUM] CWE-20 CVE-2010-0312: The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remo
The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).
nvd
CVE-2010-2927P4MEDIUMCVSS 5.0≤ 6.0.0.8v6.0+1 more2010-08-02
CVE-2010-2927 [MEDIUM] CWE-287 CVE-2010-2927: The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006
The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.
nvd
1 / 3Next →