Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-5012

EPSS 0.28% · P51
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-5012

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM Security Access Manager for Web 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM Security Access Manager(ISAM)for Web(前称IBM Tivoli Access Manager for e-business)是美国IBM公司的一套用于用户认证、授权和Web单点登录解决方案中的产品,它提供用户访问管理和Web应用保护功能。 ISAM for Web的SSH实现过程中存在安全漏洞,该漏洞源于程序没有正确限制MAC算法的设置。远程攻击者可利用该漏洞破坏加密保护机制。以下版本受到影响:ISAM for Web 7.0版本,8.0版本,9.0版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-5012

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-5012

登录查看更多情报信息。

Same Patch Batch · n/a · 2016-02-15 · 30 CVEs total

CVE-2015-5042IBM Emptoris Contract Management 任意代码执行漏洞
CVE-2016-0701OpenSSL 信息泄露漏洞
CVE-2015-3197OpenSSL 安全漏洞
CVE-2016-2314Huawei SmartAX MT882 GlobespanVirata ftpd 拒绝服务漏洞
CVE-2016-2231Huawei SmartAX MT882 Windows-based Host Interface Program服务拒绝服务漏洞
CVE-2015-8797Apache Solr Admin UI 跨站脚本漏洞
CVE-2015-8796Apache Solr Admin UI 跨站脚本漏洞
CVE-2015-8795Apache Solr Admin UI 跨站脚本漏洞
CVE-2015-8531IBM Security Access Manager for Web 跨站脚本漏洞
CVE-2015-7492IBM InfoSphere Master Data Management Reference Data Management 跨站脚本漏洞
CVE-2015-7472IBM WebSphere Portal 安全漏洞
CVE-2015-7444IBM WebSphere Commerce Enterprise Update Installer 安全漏洞
CVE-2015-7408IBM Spectrum Protect 安全漏洞
CVE-2015-7398IBM Emptoris Contract Management 跨站脚本漏洞
CVE-2015-5050IBM Emptoris Contract Management 跨站请求伪造漏洞
CVE-2016-0231多款IBM产品安全漏洞
CVE-2015-5010IBM Security Access Manager for Web 安全漏洞
CVE-2015-4991IBM SPSS Modeler 安全漏洞
CVE-2015-4957IBM QRadar SIEM Web UI 跨站脚本漏洞
CVE-2015-4956IBM QRadar SIEM Web UI 安全漏洞

Showing top 20 of 30 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-5012

No comments yet


Leave a comment