Ibm Tivoli Directory Server vulnerabilities

43 known vulnerabilities affecting ibm/tivoli_directory_server.

Total CVEs
43
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM34LOW4

Vulnerabilities

Page 2 of 3
CVE-2010-4789MEDIUMCVSS 4.0v6.0v6.0.0.0+22 more2011-04-21
CVE-2010-4789 [MEDIUM] CWE-399 CVE-2010-4789: Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) Use-after-free vulnerability in the proxy-server implementation in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.65 (aka 6.0.0.8-TIV-ITDS-IF0007) and 6.3 before 6.3.0.1 (aka 6.3.0.0-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (daemon crash) via a paged search that is interrupted by an LDAP Unbind operation.
nvd
CVE-2010-4788MEDIUMCVSS 4.0v6.0v6.0.0.0+18 more2011-04-21
CVE-2010-4788 [MEDIUM] CWE-20 CVE-2010-4788: IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) does not perform certain locking of linked-list access, which allows remote authenticated users to cause a denial of service (daemon crash) via a paged search.
nvd
CVE-2010-4785MEDIUMCVSS 4.0v6.0v6.0.0.0+18 more2011-04-21
CVE-2010-4785 [MEDIUM] CWE-399 CVE-2010-4785: The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the NULL operation OID.
nvd
CVE-2009-5073MEDIUMCVSS 4.0v6.0v6.0.0.0+15 more2011-04-21
CVE-2009-5073 [MEDIUM] CWE-399 CVE-2009-5073: IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote au IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.59 (aka 6.0.0.8-TIV-ITDS-IF0001) allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) by adding a nested group that contains the Distinguished Name (DN) of its parent entry.
nvd
CVE-2008-7289MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7289 [MEDIUM] CWE-20 CVE-2008-7289: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the si IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.
nvd
CVE-2011-1821MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2011-1821 [MEDIUM] CWE-399 CVE-2011-1821: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authen IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010 on Windows allows remote authenticated users to cause a denial of service (daemon hang) via a cn=changelog search.
nvd
CVE-2008-7288MEDIUMCVSS 5.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7288 [MEDIUM] CWE-399 CVE-2008-7288: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilization) via an anonymous DIGEST-MD5 LDAP Bind operation.
nvd
CVE-2007-6743MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2007-6743 [MEDIUM] CWE-399 CVE-2007-6743: Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 al Double free vulnerability in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0005 allows remote authenticated users to cause a denial of service (ABEND) via search operations that trigger recursive filter_free calls.
nvd
CVE-2007-6742MEDIUMCVSS 6.8v5.2.0v5.2.0.42011-04-21
CVE-2007-6742 [MEDIUM] CWE-399 CVE-2007-6742: The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.
nvd
CVE-2008-7287MEDIUMCVSS 4.0v5.2.0v5.2.0.42011-04-21
CVE-2008-7287 [MEDIUM] CWE-399 CVE-2008-7287: Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivol Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making many function calls.
nvd
CVE-2011-1820LOWCVSS 1.7v5.2.0v5.2.0.4+82 more2011-04-21
CVE-2011-1820 [LOW] CWE-200 CVE-2011-1820: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0 IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.0.0-TIV-ITDS-IF0003) does not properly handle the ibm-auditAttributesOnGroupEvalOp setting for auditi
nvd
CVE-2011-1822LOWCVSS 2.1v5.2.0v5.2.0.42011-04-21
CVE-2011-1822 [LOW] CWE-255 CVE-2011-1822: The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local users to obtain sensitive information by reading this log.
nvd
CVE-2010-4217MEDIUMCVSS 5.0v6.0.0.0v6.0.0.1+22 more2010-11-09
CVE-2010-4217 [MEDIUM] CWE-399 CVE-2010-4217: Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.
nvd
CVE-2010-4216MEDIUMCVSS 5.0v6.0v6.0.0.7+1 more2010-11-09
CVE-2010-4216 [MEDIUM] CWE-119 CVE-2010-4216: IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.
nvd
CVE-2010-2927MEDIUMCVSS 5.0≤ 6.0.0.8v6.0+1 more2010-08-02
CVE-2010-2927 [MEDIUM] CWE-287 CVE-2010-2927: The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.
nvd
CVE-2010-0312MEDIUMCVSS 5.0v6.22010-01-14
CVE-2010-0312 [MEDIUM] CWE-20 CVE-2010-0312: The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remo The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).
nvd
CVE-2009-3089HIGHCVSS 7.8v6.02009-09-08
CVE-2009-3089 [HIGH] CVE-2009-3089: IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL poi IBM Tivoli Directory Server (TDS) 6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors, related to (1) the ibmslapd.exe daemon on Windows and (2) the ibmdiradm daemon in the administration server on Linux, as demonstrated by certain modules in VulnDisco Pack Professional 8.11, a different v
nvd
CVE-2009-3088HIGHCVSS 7.5v6.02009-09-08
CVE-2009-3088 [HIGH] CWE-119 CVE-2009-3088: Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows rem Heap-based buffer overflow in ibmdiradm in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to have an unspecified impact via unknown vectors that trigger heap corruption, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because th
nvd
CVE-2009-3090MEDIUMCVSS 5.0v6.02009-09-08
CVE-2009-3090 [MEDIUM] CVE-2009-3090: Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers Unspecified vulnerability in IBM Tivoli Directory Server (TDS) 6.0 on Linux allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, t
nvd
CVE-2008-2943MEDIUMCVSS 6.0PoCv6.1.0.0v6.1.0.1+14 more2008-06-30
CVE-2008-2943 [MEDIUM] CWE-399 CVE-2008-2943: Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remot Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulne
nvd