Vulnerabilities > CVE-2008-5035 - Resource Management Errors vulnerability in IBM Hardware Management Console 3.2.0/3.3.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 32181 CVE(CAN) ID: CVE-2008-5035 IBM的硬件管理控制台(HMC)是用于控制系统及与受控系统通讯的系统管理设备。 HMC的资源监控和控制(RMC)守护程序在处理恶意请求报文时存在拒绝服务漏洞,如果远程攻击者发送了带有无效长度的畸形报文的话,就可以导致守护程序崩溃或挂起。 IBM Hardware Management Console 7 R3.3.0 SP2 IBM Hardware Management Console 7 R3.2.0 SP1 IBM --- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=https://www14.software.ibm.com/webapp/set2/sas/f/hmc/home.html target=_blank>https://www14.software.ibm.com/webapp/set2/sas/f/hmc/home.html</a> |
id | SSV:4430 |
last seen | 2017-11-19 |
modified | 2008-11-12 |
published | 2008-11-12 |
reporter | Root |
title | IBM硬件管理控制台RMC守护程序远程拒绝服务漏洞 |
References
- http://secunia.com/advisories/32571
- http://www.securityfocus.com/bid/32181
- http://www.vupen.com/english/advisories/2008/3051
- http://www-1.ibm.com/support/docview.wss?uid=isg1MB02482
- http://www-1.ibm.com/support/docview.wss?uid=isg1MB02485
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4441
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4442
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46413
- https://www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html#MH01133
- https://www14.software.ibm.com/webapp/set2/sas/f/hmc/power6/install/v7.Readme.html#MH01134