Vulnerability Name:

CVE-2012-2190 (CCN-75994)

Assigned:2012-07-30
Published:2012-07-30
Updated:2017-08-29
Summary:IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-310
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2012-2190

Source: CCN
Type: SA52391
IBM DB2 / DB2 Connect Global Security Toolkit Multiple Vulnerabilities

Source: CCN
Type: SA53067
IBM Informix Products Global Security Toolkit Multiple Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 1606096
Security Vulnerabilities fixed in IBM WebSphere Application Server 8.0.0.4

Source: CCN
Type: IBM Security Bulletin 1620711
IBM Informix Cryptographic Library Updates (CVE-2012-2190, CVE-2012-2191, CVE-2012-2203)

Source: AIXAPAR
Type: UNKNOWN
PM66218

Source: CONFIRM
Type: Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21606096

Source: CCN
Type: IBM Security Alert 1606145
Two GKIT vulnerabilities impact Rational Directory Server 5.2.x (Tivoli)

Source: CCN
Type: IBM Security Bulletin 1607366
Two security vulnerabilities found and fixed in WebSphere Business Events V7.0, V7.0.1 and 7.0.1.1 in the DesignData Tooling (CVE-2012-2190, CVE-2012-2191)

Source: CCN
Type: IBM Security Bulletin 1609030
GSKit SSL/TLS handshake vulnerability in Tivoli Directory Server (CVE-2012-2190)

Source: CCN
Type: IBM Security Bulletin 1613589
TPM for OSd / Images multiple vulnerabilities when GSKit is configured

Source: CCN
Type: IBM Security Bulletin 1614265
Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.0.1

Source: CCN
Type: IBM Security Bulletin 1622585
IBM Tivoli Monitoring GSKIT vulnerabilities (CVE-2012-2203, CVE-2012-2191, CVE-2012-2190)

Source: CCN
Type: IBM Security Bulletin 1626749
Multiple GSKit Vulnerabilities in IBM DB2 (CVE-2012-2190, CVE-2012-2191, CVE-2012-2203)

Source: CCN
Type: IBM Security Bulletin 1640752
Multiple vulnerabilities in Product IBM Application Manager For Smart Business 1.2.1 (CVE-2013-0548, CVE-2013-0551, CVE-2013-0576 , CVE-2013-2960, CVE-2013-2961, CVE-2012-2190, CVE-2012-2191, CVE-2012-2203)

Source: CCN
Type: IBM Security Bulletin 1643698
GSKit Security Vulnerabilities addressed in IBM Tivoli Network Manager 3.8 and 3.9

Source: CCN
Type: IBM Security Bulletin 1650623
GSKit Security Vulnerabilities addressed in IBM Tivoli Netcool OMNIbus

Source: CCN
Type: IBM Security Bulletin 1651227
IBM SmartCloud Analytics - Log Analysis - Security exposures related to GSKit embedded with IBM Tivoli Monitoring components (CVE-2012-2203, CVE-2012-2191,CVE-2012-2190)

Source: CCN
Type: IBM Security Bulletin 1653034
IBM Tivoli Composite Application Manager for Transactions affected by multiple vulnerabilities in GSKit (CVE-2012-2203, CVE-2012-2191, CVE-2012-2190)

Source: CCN
Type: BID-55185
Multiple IBM products GSKit Client Hello Message Remote Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
ibm-multiple-gskit-hello-dos(75994)

Source: XF
Type: UNKNOWN
ibm-multiple-gskit-hello-dos(75994)

Source: CCN
Type: IBM Security Bulletin 1611311
Security Vulnerabilities fixed in IBM WebSphere Application Server 6.1.0.45

Source: CCN
Type: IBM Security Bulletin 1611313
Security Vulnerabilities fixed in IBM WebSphere Application Server 7.0.0.25

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_application_server:6.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.12:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.15:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.17:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.19:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.21:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.23:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.25:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.27:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.29:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.31:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.33:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.35:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.37:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.39:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.41:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:6.1.0.43:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.13:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.15:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.17:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.19:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.21:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0.0.23:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:ibm:websphere_application_server:8.0.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0.0.3:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:ibm:websphere_application_server:8.5.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere application server 6.1.0
    ibm websphere application server 6.1.0.0
    ibm websphere application server 6.1.0.1
    ibm websphere application server 6.1.0.2
    ibm websphere application server 6.1.0.3
    ibm websphere application server 6.1.0.5
    ibm websphere application server 6.1.0.7
    ibm websphere application server 6.1.0.9
    ibm websphere application server 6.1.0.11
    ibm websphere application server 6.1.0.12
    ibm websphere application server 6.1.0.15
    ibm websphere application server 6.1.0.17
    ibm websphere application server 6.1.0.19
    ibm websphere application server 6.1.0.21
    ibm websphere application server 6.1.0.23
    ibm websphere application server 6.1.0.25
    ibm websphere application server 6.1.0.27
    ibm websphere application server 6.1.0.29
    ibm websphere application server 6.1.0.31
    ibm websphere application server 6.1.0.33
    ibm websphere application server 6.1.0.35
    ibm websphere application server 6.1.0.37
    ibm websphere application server 6.1.0.39
    ibm websphere application server 6.1.0.41
    ibm websphere application server 6.1.0.43
    ibm websphere application server 7.0
    ibm websphere application server 7.0.0.1
    ibm websphere application server 7.0.0.2
    ibm websphere application server 7.0.0.3
    ibm websphere application server 7.0.0.4
    ibm websphere application server 7.0.0.5
    ibm websphere application server 7.0.0.6
    ibm websphere application server 7.0.0.7
    ibm websphere application server 7.0.0.8
    ibm websphere application server 7.0.0.9
    ibm websphere application server 7.0.0.11
    ibm websphere application server 7.0.0.13
    ibm websphere application server 7.0.0.15
    ibm websphere application server 7.0.0.17
    ibm websphere application server 7.0.0.19
    ibm websphere application server 7.0.0.21
    ibm websphere application server 7.0.0.23
    ibm websphere application server 8.0.0.0
    ibm websphere application server 8.0.0.1
    ibm websphere application server 8.0.0.2
    ibm websphere application server 8.0.0.3
    ibm websphere application server 8.5.0.0