CVE-2011-1560

IBM Soliddb < 4.5.180 - Credentials Management

Title source: rule
STIX 2.1

Description

solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.

References (6)

Core 6
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21474552
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/71494
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44030
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/66455
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0854
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-11-115/

Scores

EPSS 0.0399
EPSS Percentile 89.4%

Details

CWE
CWE-255
Status published
Products (26)
ibm/soliddb 4.5.167
ibm/soliddb 4.5.168
ibm/soliddb 4.5.169
ibm/soliddb 4.5.173
ibm/soliddb 4.5.175
ibm/soliddb 4.5.176
ibm/soliddb 4.5.178
ibm/soliddb 4.5.179
ibm/soliddb 6.0.1060
ibm/soliddb 6.0.1061
... and 16 more
Published Apr 05, 2011
Tracked Since Feb 18, 2026