← Back

CVE-2011-1560

nvd nist
Published: Apr 5, 2011Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which allows remote attackers to bypass authentication via a short length value.

Affected (26)

Products: Ibm: Soliddb
1 product
Soliddb
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Up to 4.5.180
Version 4.5.167
Version 4.5.168
Version 4.5.169
Version 4.5.173
Version 4.5.175
Version 4.5.176
Version 4.5.178
Version 4.5.179
Configuration B
17 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 6.0.1060
Version 6.0.1061
Version 6.0.1064
Version 6.0.1065
Version 6.0.1066
Version 6.1.18
Version 6.1.20
Version 6.1
Version 6.3.33
Version 6.3.37
Version 6.3.38
Version 6.30.0039
Version 6.30.0040
Version 6.30.0044
Version 6.5.0.0
Version 6.5.0.1
Version 6.5.0.2

Related CWEs

References (12)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.