Vulnerabilities > CVE-2008-5035 - Resource Management Errors vulnerability in IBM Hardware Management Console 3.2.0/3.3.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
ibm
CWE-399

Summary

The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.

Vulnerable Configurations

Part Description Count
Application
Ibm
2

Common Weakness Enumeration (CWE)

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 32181 CVE(CAN) ID: CVE-2008-5035 IBM的硬件管理控制台(HMC)是用于控制系统及与受控系统通讯的系统管理设备。 HMC的资源监控和控制(RMC)守护程序在处理恶意请求报文时存在拒绝服务漏洞,如果远程攻击者发送了带有无效长度的畸形报文的话,就可以导致守护程序崩溃或挂起。 IBM Hardware Management Console 7 R3.3.0 SP2 IBM Hardware Management Console 7 R3.2.0 SP1 IBM --- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=https://www14.software.ibm.com/webapp/set2/sas/f/hmc/home.html target=_blank>https://www14.software.ibm.com/webapp/set2/sas/f/hmc/home.html</a>
idSSV:4430
last seen2017-11-19
modified2008-11-12
published2008-11-12
reporterRoot
titleIBM硬件管理控制台RMC守护程序远程拒绝服务漏洞