CVE-2015-5012
HIGHIBM Security Access Manager for Web 7.0-8.0 and 9.0 - SSH MAC Algorithm Downgrade
Title source: llmDescription
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
References (3)
Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971422
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV78768
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV78780
Scores
CVSS v3
7.5
EPSS
0.0155
EPSS Percentile
72.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-310
Status
published
Products (26)
ibm/security_access_manager_9.0_firmware
9.0.0
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.1
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.2
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.3
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.4
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.5
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.6
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.7
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.8
ibm/security_access_manager_for_web_7.0_firmware
7.0.0.9
... and 16 more
Published
Feb 15, 2016
Tracked Since
Feb 18, 2026