CVE-2021-29725

IBM Secure External Authentication Server 2.4.3.2, 6.0.1, 6.0.2 and IBM Secure Proxy 3.4.3.2, 6.0.1, 6.0.2 could allow a remote user to consume resources causing a denial of service due to a resource leak.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:secure_external_authentication_server:2.4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_external_authentication_server:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_external_authentication_server:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:3.4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:6.0.2:*:*:*:*:*:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*

History

19 Mar 2024, 17:10

Type Values Removed Values Added
First Time Ibm sterling Secure Proxy
CPE cpe:2.3:a:ibm:secure_proxy:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_proxy:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_proxy:3.4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:3.4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_secure_proxy:6.0.1:*:*:*:*:*:*:*

31 Jul 2021, 01:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-770
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/201102 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/201102 - VDB Entry, Vendor Advisory
References (CONFIRM) https://www.ibm.com/support/pages/node/6471615 - (CONFIRM) https://www.ibm.com/support/pages/node/6471615 - Patch, Vendor Advisory
References (CONFIRM) https://www.ibm.com/support/pages/node/6471577 - (CONFIRM) https://www.ibm.com/support/pages/node/6471577 - Patch, Vendor Advisory
CPE cpe:2.3:a:ibm:secure_external_authentication_server:2.4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_proxy:6.0.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_proxy:3.4.3.2:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:-:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_proxy:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_external_authentication_server:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:secure_external_authentication_server:6.0.1:*:*:*:*:*:*:*

15 Jul 2021, 16:39

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-15 16:15

Updated : 2024-03-19 17:10


NVD link : CVE-2021-29725

Mitre link : CVE-2021-29725

CVE.ORG link : CVE-2021-29725


JSON object : View

Products Affected

oracle

  • solaris

ibm

  • aix
  • sterling_secure_proxy
  • secure_external_authentication_server

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-770

Allocation of Resources Without Limits or Throttling