Vulnerability Name: CVE-2012-2190 (CCN-75994) Assigned: 2012-07-30 Published: 2012-07-30 Updated: 2017-08-29 Summary: IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-310 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2012-2190 Source: CCN Type: SA52391IBM DB2 / DB2 Connect Global Security Toolkit Multiple Vulnerabilities Source: CCN Type: SA53067IBM Informix Products Global Security Toolkit Multiple Vulnerabilities Source: CCN Type: IBM Security Bulletin 1606096Security Vulnerabilities fixed in IBM WebSphere Application Server 8.0.0.4 Source: CCN Type: IBM Security Bulletin 1620711IBM Informix Cryptographic Library Updates (CVE-2012-2190, CVE-2012-2191, CVE-2012-2203) Source: AIXAPAR Type: UNKNOWNPM66218 Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=swg21606096 Source: CCN Type: IBM Security Alert 1606145Two GKIT vulnerabilities impact Rational Directory Server 5.2.x (Tivoli) Source: CCN Type: IBM Security Bulletin 1607366Two security vulnerabilities found and fixed in WebSphere Business Events V7.0, V7.0.1 and 7.0.1.1 in the DesignData Tooling (CVE-2012-2190, CVE-2012-2191) Source: CCN Type: IBM Security Bulletin 1609030GSKit SSL/TLS handshake vulnerability in Tivoli Directory Server (CVE-2012-2190) Source: CCN Type: IBM Security Bulletin 1613589TPM for OSd / Images multiple vulnerabilities when GSKit is configured Source: CCN Type: IBM Security Bulletin 1614265Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.0.1 Source: CCN Type: IBM Security Bulletin 1622585IBM Tivoli Monitoring GSKIT vulnerabilities (CVE-2012-2203, CVE-2012-2191, CVE-2012-2190) Source: CCN Type: IBM Security Bulletin 1626749Multiple GSKit Vulnerabilities in IBM DB2 (CVE-2012-2190, CVE-2012-2191, CVE-2012-2203) Source: CCN Type: IBM Security Bulletin 1640752Multiple vulnerabilities in Product IBM Application Manager For Smart Business 1.2.1 (CVE-2013-0548, CVE-2013-0551, CVE-2013-0576 , CVE-2013-2960, CVE-2013-2961, CVE-2012-2190, CVE-2012-2191, CVE-2012-2203) Source: CCN Type: IBM Security Bulletin 1643698GSKit Security Vulnerabilities addressed in IBM Tivoli Network Manager 3.8 and 3.9 Source: CCN Type: IBM Security Bulletin 1650623GSKit Security Vulnerabilities addressed in IBM Tivoli Netcool OMNIbus Source: CCN Type: IBM Security Bulletin 1651227IBM SmartCloud Analytics - Log Analysis - Security exposures related to GSKit embedded with IBM Tivoli Monitoring components (CVE-2012-2203, CVE-2012-2191,CVE-2012-2190) Source: CCN Type: IBM Security Bulletin 1653034IBM Tivoli Composite Application Manager for Transactions affected by multiple vulnerabilities in GSKit (CVE-2012-2203, CVE-2012-2191, CVE-2012-2190) Source: CCN Type: BID-55185Multiple IBM products GSKit Client Hello Message Remote Denial of Service Vulnerability Source: XF Type: UNKNOWNibm-multiple-gskit-hello-dos(75994) Source: XF Type: UNKNOWNibm-multiple-gskit-hello-dos(75994) Source: CCN Type: IBM Security Bulletin 1611311Security Vulnerabilities fixed in IBM WebSphere Application Server 6.1.0.45 Source: CCN Type: IBM Security Bulletin 1611313Security Vulnerabilities fixed in IBM WebSphere Application Server 7.0.0.25 Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.12:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.17:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.21:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.23:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.25:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.27:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.29:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.31:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.33:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.35:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.37:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.39:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.41:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:6.1.0.43:*:*:*:*:*:*:* Configuration 2 :cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.6:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:* Configuration 3 :cpe:/a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:* OR cpe:/a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:* Configuration 4 :cpe:/a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm websphere application server 6.1.0
ibm websphere application server 6.1.0.0
ibm websphere application server 6.1.0.1
ibm websphere application server 6.1.0.2
ibm websphere application server 6.1.0.3
ibm websphere application server 6.1.0.5
ibm websphere application server 6.1.0.7
ibm websphere application server 6.1.0.9
ibm websphere application server 6.1.0.11
ibm websphere application server 6.1.0.12
ibm websphere application server 6.1.0.15
ibm websphere application server 6.1.0.17
ibm websphere application server 6.1.0.19
ibm websphere application server 6.1.0.21
ibm websphere application server 6.1.0.23
ibm websphere application server 6.1.0.25
ibm websphere application server 6.1.0.27
ibm websphere application server 6.1.0.29
ibm websphere application server 6.1.0.31
ibm websphere application server 6.1.0.33
ibm websphere application server 6.1.0.35
ibm websphere application server 6.1.0.37
ibm websphere application server 6.1.0.39
ibm websphere application server 6.1.0.41
ibm websphere application server 6.1.0.43
ibm websphere application server 7.0
ibm websphere application server 7.0.0.1
ibm websphere application server 7.0.0.2
ibm websphere application server 7.0.0.3
ibm websphere application server 7.0.0.4
ibm websphere application server 7.0.0.5
ibm websphere application server 7.0.0.6
ibm websphere application server 7.0.0.7
ibm websphere application server 7.0.0.8
ibm websphere application server 7.0.0.9
ibm websphere application server 7.0.0.11
ibm websphere application server 7.0.0.13
ibm websphere application server 7.0.0.15
ibm websphere application server 7.0.0.17
ibm websphere application server 7.0.0.19
ibm websphere application server 7.0.0.21
ibm websphere application server 7.0.0.23
ibm websphere application server 8.0.0.0
ibm websphere application server 8.0.0.1
ibm websphere application server 8.0.0.2
ibm websphere application server 8.0.0.3
ibm websphere application server 8.5.0.0