SB2025010306 - Multiple vulnerabilities in IBM Security Directory Integrator
Published: January 3, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2023-32328)
The vulnerability allows a remote attacker to take control of the server.
The vulnerability exists due to software uses uses insecure protocols in some instances. A remote attacker with ability to intercept network traffic can take control of the server.
2) Improper Certificate Validation (CVE-ID: CVE-2023-43017)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can install a configuration file that could allow remote access.
3) OS Command Injection (CVE-ID: CVE-2022-2068)
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in the c_rehash script distributed by some operating systems. A remote attacker with ability to pass data to c_rehash script can and execute arbitrary OS commands with the privileges of the script.
The vulnerability exists due to incomplete fix for #VU62765 (CVE-2022-1292).
Remediation
Install update from vendor's website.