Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 4 |
CVE-ID | CVE-2012-5783 CVE-2014-3577 CVE-2012-6153 CVE-2015-5262 |
CWE-ID | CWE-295 CWE-20 CWE-399 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Control Desk Other software / Other software solutions |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains information about 4 vulnerabilities.
EUVDB-ID: #VU80741
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2012-5783
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a man-in-the-middle attack to spoof SSL servers via an arbitrary valid certificate.
The vulnerability exists due to Apache Commons HttpClient does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. A remote attacker can perform a man-in-the-middle attack to spoof SSL servers via an arbitrary valid certificate.
MitigationInstall update from vendor's website.
Vulnerable software versionsControl Desk: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6847289
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU57150
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2014-3577
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation. A remote attacker can perform a man-in-the-middle (MitM) attack and spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate.
MitigationInstall update from vendor's website.
Vulnerable software versionsControl Desk: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6847289
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77628
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2012-6153
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to modify files on the system.
The vulnerability exists due to Apache Commons HttpClient does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate. A remote attacker can pass specially crafted input to the application and modify files on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsControl Desk: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6847289
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU80908
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2015-5262
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsControl Desk: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6847289
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?