SB2025010306 - Multiple vulnerabilities in IBM Security Directory Integrator



SB2025010306 - Multiple vulnerabilities in IBM Security Directory Integrator

Published: January 3, 2025

Security Bulletin ID SB2025010306
Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 33% Medium 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Cleartext transmission of sensitive information (CVE-ID: CVE-2023-32328)

The vulnerability allows a remote attacker to take control of the server.

The vulnerability exists due to software uses uses insecure protocols in some instances. A remote attacker with ability to intercept network traffic can take control of the server.


2) Improper Certificate Validation (CVE-ID: CVE-2023-43017)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote attacker can install a configuration file that could allow remote access.


3) OS Command Injection (CVE-ID: CVE-2022-2068)

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the c_rehash script distributed by some operating systems. A remote attacker with ability to pass data to c_rehash script can and execute arbitrary OS commands with the privileges of the script.

The vulnerability exists due to incomplete fix for #VU62765 (CVE-2022-1292).


Remediation

Install update from vendor's website.