Vulnerability Description
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Access Manager 9.0 Firmware | 9.0.0 |
| Ibm | Security Access Manager For Web 7.0 Firmware | 7.0.0.1 |
| Ibm | Security Access Manager For Web 8.0 Firmware | 8.0.0.1 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV78768
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV78780
- http://www-01.ibm.com/support/docview.wss?uid=swg21971422PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV78768
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV78780
- http://www-01.ibm.com/support/docview.wss?uid=swg21971422PatchVendor Advisory
FAQ
What is CVE-2015-5012?
CVE-2015-5012 is a vulnerability with a CVSS score of 7.5 (HIGH). The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms,...
How severe is CVE-2015-5012?
CVE-2015-5012 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5012?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Access Manager 9.0 Firmware, Ibm Security Access Manager For Web 7.0 Firmware, Ibm Security Access Manager For Web 8.0 Firmware.