Vulnerability Name:

CVE-2013-6329 (CCN-88939)

Assigned:2013-12-10
Published:2013-12-10
Updated:2017-08-29
Summary:IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-310
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-6329

Source: CCN
Type: SA56001
IBM Content Manager OnDemand GSKit SSLv2 Session Resuming Denial of Service Vulnerability

Source: CCN
Type: SA56031
IBM Tivoli Access Manager for e-business / Security Access Manager for Web GSKit Vulnerability

Source: CCN
Type: SA56058
IBM HTTP Server GSKit SSLv2 Session Resuming Denial of Service Vulnerability

Source: SECUNIA
Type: UNKNOWN
56058

Source: CCN
Type: SA56409
IBM Informix Products GSKit SSLv2 Session Resuming Denial of Service Vulnerability

Source: CCN
Type: SA56466
IBM TXSeries for Multiplatforms GSKit SSLv2 Session Resuming Denial of Service Vulnerability

Source: CCN
Type: SA56635
IBM Global Security ToolKit SSLv2 Session Resuming Denial of Service Vulnerability

Source: CCN
Type: SA56960
IBM Tivoli Netcool/OMNIbus Global Security Toolkit Two Denial of Service Vulnerabilities

Source: CCN
Type: IBM Security Bulletin 1659548
Potential Denial of service vulnerability in IBM HTTP Server (CVE-2013-6329)

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg21659548

Source: CCN
Type: IBM Security Bulletin 1659716
CM OnDemand GSKit SSLV2 Resuming SSLV3 Vulnerability (CVE-2013-6329)

Source: CONFIRM
Type: Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21659716

Source: CCN
Type: IBM Security Bulletin 1659837
GSKit SSL negotiation vulnerability in Tivoli Access Manager for e-business (CVE-2013-6329)

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg21659837

Source: CCN
Type: IBM Security Bulletin 1660286
IBM Rational ClearCase CCRC WAN Server remote denial of service (CVE-2013-6329)

Source: CCN
Type: IBM Security Bulletin 1661497
GSKit SSL negotiation vulnerability in TPM for OS Deployment and TPM for Images (CVE-2013-6329)

Source: CCN
Type: IBM Security Bulletin 1662110
Tivoli Netcool/OMNIbus Web GUI can be affected by a vulnerability in the IBM GSKit library (CVE-2013-6329)

Source: CCN
Type: IBM Security Bulletin 1662362
GSKit SSL negotiation vulnerability in Tivoli Directory Server (CVE-2013-6329)

Source: CCN
Type: IBM Security Bulletin 1663362
TXSeries for Multiplatforms V7.1 : Security vulnerability in using GSKit 8 version with IBM TXSeries for Multiplatforms Version 7.1 (CVE-2013-6329)

Source: CCN
Type: IBM Security Bulletin 1663428
Tivoli Netcool/OMNIbus can be affected by vulnerabilities in the IBM GSKit library

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21669554

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21676091

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21676092

Source: CCN
Type: IBM Security Bulletin 1660440
Potential SSL/TLS-related denial of service vulnerability in IBM Informix Client SDK (CVE-2013-6329)

Source: CCN
Type: IBM Security Bulletin 1662902
GSKit certificate chain vulnerability in IBM Security Directory Server and Tivoli Directory Server (CVE-2013-6747)

Source: CCN
Type: IBM Security Bulletin 1669554
Potential Security Vulnerabilities fixed in IBM WebSphere Application Server 8.5.5.2

Source: CCN
Type: IBM Security Bulletin 1676091
Potential Security Vulnerabilities fixed in IBM WebSphere Application Server 7.0.0.33

Source: CCN
Type: IBM Security Bulletin 1676092
Potential Security Vulnerabilities fixed in IBM WebSphere Application Server 8.0.0.9

Source: CCN
Type: IBM Security Bulletin 1685323
Potential Security Vulnerability in IBM Tivoli Monitoring GSKit (CVE-2014-6747, CVE-2013-6329, CVE-2014-0169)

Source: CCN
Type: IBM Security Bulletin 1700834
Ephemeral RSA Vulnerability in Communications Server for Data Center Deployment, Communications Server for AIX, Communications Server for Linux, Communications Server for Linux on System z, Communications Server for Windows (CVE-2015-0

Source: CCN
Type: OSVDB ID: 100864
Content Manager OnDemand for Multiplatform SSLv2 Session Resumption Handling Remote DoS

Source: CCN
Type: BID-64249
IBM Global Security Kit CVE-2013-6329 Remote Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
ibm-gskit-cve20136329-dos(88939)

Source: XF
Type: UNKNOWN
ibm-gskit-cve20136329-dos(88939)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:content_manager_ondemand_for_multiplatforms:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:content_manager_ondemand_for_multiplatforms:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:global_security_kit:-:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:6.0:*:web:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:6.1:*:web:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:6.1.1:*:web:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:7.0:*:web:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_application_server:6.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:http_server:6.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_clearcase:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:rational_clearcase:7.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:http_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/omnibus:7.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_directory_server:-:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:http_server:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:http_server:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_application_server:8.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:content_manager_ondemand_for_multiplatforms:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:content_manager_ondemand_for_multiplatforms:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/omnibus:7.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_netcool/omnibus:7.4.0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:6.0:*:web:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:6.1:*:web:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:6.1.1:*:web:*:*:*:*:*
  • OR cpe:/o:ibm:security_access_manager:7.0:*:web:*:*:*:*:*
  • OR cpe:/a:ibm:rational_clearcase:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_directory_server:6.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_directory_server:6.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_directory_server:6.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_directory_server:6.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_monitoring:6.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_monitoring:6.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_monitoring:6.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_monitoring:6.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_monitoring:6.2.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm content manager ondemand for multiplatforms 8.5
    ibm content manager ondemand for multiplatforms 9.0
    ibm global security kit -
    ibm security access manager for web 6.0
    ibm security access manager for web 6.1
    ibm security access manager for web 6.1.1
    ibm security access manager for web 7.0
    ibm websphere application server 6.1
    ibm http server 6.1
    ibm rational clearcase 7.0
    ibm websphere application server 7.0
    ibm rational clearcase 7.1
    ibm http server 7.0
    ibm tivoli netcool/omnibus 7.3.0
    ibm websphere application server 8.0
    ibm tivoli directory server -
    ibm websphere application server 8.5
    ibm http server 8.0
    ibm http server 8.5
    ibm websphere application server 8.5.5
    ibm content manager ondemand for multiplatforms 8.5
    ibm content manager ondemand for multiplatforms 9.0
    ibm tivoli netcool/omnibus 7.3.1
    ibm tivoli netcool/omnibus 7.4.0
    ibm security access manager for web 6.0
    ibm security access manager for web 6.1
    ibm security access manager for web 6.1.1
    ibm security access manager 7.0
    ibm rational clearcase 8.0
    ibm security directory server 6.1
    ibm security directory server 6.2
    ibm security directory server 6.3
    ibm security directory server 6.3.1
    ibm tivoli monitoring 6.2.2
    ibm tivoli monitoring 6.2.3
    ibm tivoli monitoring 6.3.0
    ibm tivoli monitoring 6.2.0
    ibm tivoli monitoring 6.2.1