CVE Vulnerabilities

CVE-2015-5012

Published: Feb 15, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Security_access_manager_9.0_firmwareIbm9.0.0 (including)9.0.0 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.1 (including)7.0.0.1 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.2 (including)7.0.0.2 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.3 (including)7.0.0.3 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.4 (including)7.0.0.4 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.5 (including)7.0.0.5 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.6 (including)7.0.0.6 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.7 (including)7.0.0.7 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.8 (including)7.0.0.8 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.9 (including)7.0.0.9 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.10 (including)7.0.0.10 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.11 (including)7.0.0.11 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.12 (including)7.0.0.12 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.13 (including)7.0.0.13 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.14 (including)7.0.0.14 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.15 (including)7.0.0.15 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.16 (including)7.0.0.16 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.17 (including)7.0.0.17 (including)
Security_access_manager_for_web_7.0_firmwareIbm7.0.0.18 (including)7.0.0.18 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.0.1 (including)8.0.0.1 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.0.2 (including)8.0.0.2 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.0.3 (including)8.0.0.3 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.0.5 (including)8.0.0.5 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.1 (including)8.0.1 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.1.0 (including)8.0.1.0 (including)
Security_access_manager_for_web_8.0_firmwareIbm8.0.1.2 (including)8.0.1.2 (including)

References