CVE-2015-0138 - CVE House
Back to Database
Status published Medium CVE-2015-0138

GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073,...

Vulnerability Description

GSKit in IBM Tivoli Directory Server (ITDS) 6.0 before 6.0.0.73-ISS-ITDS-IF0073, 6.1 before 6.1.0.66-ISS-ITDS-IF0066, 6.2 before 6.2.0.42-ISS-ITDS-IF0042, and 6.3 before 6.3.0.35-ISS-ITDS-IF0035 and IBM Security Directory Server (ISDS) 6.3.1 before 6.3.1.9-ISS-ISDS-IF0009 does not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-0138

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tivoli directory server
Vulnerable Versions:
0, 6.1.0, 6.1.0.0, 6.1.0.1, 6.1.0.2, 6.1.0.3, 6.1.0.4, 6.1.0.5, 6.1.0.6, 6.1.0.7, 6.1.0.8, 6.1.0.9, 6.1.0.10, 6.1.0.11, 6.1.0.12, 6.1.0.13, 6.1.0.14, 6.1.0.15, 6.1.0.17, 6.1.0.18, 6.1.0.19, 6.1.0.20, 6.1.0.21, 6.1.0.22, 6.1.0.23, 6.1.0.24, 6.1.0.25, 6.1.0.26, 6.1.0.27, 6.1.0.28, 6.1.0.29, 6.1.0.30, 6.1.0.31, 6.1.0.32, 6.1.0.33, 6.1.0.34, 6.1.0.35, 6.1.0.36, 6.1.0.37, 6.1.0.38, 6.1.0.39, 6.1.0.40, 6.1.0.41, 6.1.0.42, 6.1.0.43, 6.1.0.44, 6.1.0.45, 6.1.0.46, 6.1.0.47, 6.1.0.48, 6.1.0.49, 6.1.0.50, 6.1.0.51, 6.1.0.52, 6.1.0.53, 6.1.0.54, 6.1.0.55, 6.1.0.56, 6.1.0.57, 6.1.0.58, 6.1.0.59, 6.1.0.60, 6.1.0.61, 6.1.0.62, 6.1.0.63, 6.1.0.64, 6.1.0.65, 6.1.0.66, 6.2.0.0, 6.2.0.1, 6.2.0.2, 6.2.0.3, 6.2.0.4, 6.2.0.5, 6.2.0.6, 6.2.0.7, 6.2.0.8, 6.2.0.10, 6.2.0.11, 6.2.0.12, 6.2.0.13, 6.2.0.14, 6.2.0.15, 6.2.0.19, 6.2.0.20, 6.2.0.21, 6.2.0.22, 6.2.0.23, 6.2.0.24, 6.2.0.25, 6.2.0.26, 6.2.0.27, 6.2.0.29, 6.2.0.30, 6.2.0.31, 6.2.0.32, 6.2.0.33, 6.2.0.34, 6.2.0.35, 6.2.0.36, 6.2.0.37, 6.2.0.38, 6.2.0.39, 6.2.0.40, 6.2.0.41, 6.2.0.42, 6.3.0.0, 6.3.0.1, 6.3.0.2, 6.3.0.8, 6.3.0.9, 6.3.0.10, 6.3.0.11, 6.3.0.12, 6.3.0.14, 6.3.0.15, 6.3.0.17, 6.3.0.18, 6.3.0.19, 6.3.0.21, 6.3.0.22, 6.3.0.23, 6.3.0.24, 6.3.0.25, 6.3.0.26, 6.3.0.27, 6.3.0.28, 6.3.0.29, 6.3.0.30, 6.3.0.31, 6.3.0.32, 6.3.0.33, 6.3.0.34, 6.3.0.35, 6.3.1.0, 6.3.1.5, 6.3.1.6, 6.3.1.7, 6.3.1.8, 6.3.1.9

Timeline

Official Publish: March 25th, 2015
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.