Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against IBM Director CIM Server Consumer Name Handling Denial of Service

Subscribe

Check Point Reference: CPAI-2009-059
Date Published:
Preemptive Since:
Severity:
Source: Secunia Advisory: SA34212
Industry Reference(s):

CVE-2009-0879

Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
IBM Systems Director Prior to 5.20.3
Vulnerability Description
The CIM (Common Information Model) Server of IBM Director is vulnerable to a denial-of-service condition because the application fails to properly handle specially crafted requests. A remote attacker can exploit this vulnerability by sending crafted requests to the target host. Successful exploitation could result in a denial of service (DoS) condition of System Director services on the target host.
Update/Patch Available
The vendor has not released an advisory addressing this vulnerability.
Vulnerability Details
The vulnerability is in the CIM Listener process while parsing crafted HTTP requests containing overly long Consumer Names in the URI. Successful exploitation would cause the CIM server to crash.

Protection Overview
By enabling this protection, IPS-1 will detect and block attempts to overflow the URL length while accessing the IMB CIM server.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Web Intelligence > WWW 2, and select the CGI Attacks protection group.
3. Click IBM Director CIM Server Denial of Service (CVE-2009-0879) - IPS-1 NGX R65 only.
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: WWW/CGI Attacks Protection Group
Description: IBM Director CIM Server Denial of Service (CVE-2009-0879)