Vulnerability Description
solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Soliddb | <= 4.5.180 |
Related Weaknesses (CWE)
References
- http://osvdb.org/71494
- http://secunia.com/advisories/44030
- http://www.ibm.com/support/docview.wss?uid=swg21474552Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0854
- http://www.zerodayinitiative.com/advisories/ZDI-11-115/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66455
- http://osvdb.org/71494
- http://secunia.com/advisories/44030
- http://www.ibm.com/support/docview.wss?uid=swg21474552Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0854
- http://www.zerodayinitiative.com/advisories/ZDI-11-115/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66455
FAQ
What is CVE-2011-1560?
CVE-2011-1560 is a vulnerability with a CVSS score of 9.3 (HIGH). solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attacke...
How severe is CVE-2011-1560?
CVE-2011-1560 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-1560?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Soliddb.