CVE-2015-5012

HIGH

IBM Security Access Manager for Web 7.0-8.0 and 9.0 - SSH MAC Algorithm Downgrade

Title source: llm
STIX 2.1

Description

The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971422
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV78768
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV78780

Scores

CVSS v3 7.5
EPSS 0.0155
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-310
Status published
Products (26)
ibm/security_access_manager_9.0_firmware 9.0.0
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.1
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.2
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.3
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.4
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.5
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.6
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.7
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.8
ibm/security_access_manager_for_web_7.0_firmware 7.0.0.9
... and 16 more
Published Feb 15, 2016
Tracked Since Feb 18, 2026