Tivoli Directory Server vulnerable to LDAP error that could allow for local denial-of-service attacks. IBM said it is working on developing and distributing fixes to a vulnerability detected in IBM Tivoli Directory Server 6.x that could leave the software exposed to denial-of-service attacks.According to IBM, Tivoli Directory Server 6.x provides an LDAP identity infrastructure that can serve as the foundation for deploying identity management applications and Web services. The flaw, detected earlier this week, was deemed less critical by Secunia Research, which reported the vulnerability in a security advisory. The vulnerability has been discovered in Version 6 of the software and the Web site indicates other versions could be affected.According to the Secunia security advisory, the vulnerability is caused due to an error within the LDAP server when handling certain requests, and “this can be exploited to crash the server via specially-crafted request sent to port 389/tcp.” The error can cause the server to crash due to a denial-of-service attack committed on the local network, but security experts say the threat is minimal considering the nature of the flaw.“This flaw is not as critical as some because it can only be exploited on the local network and even if it is compromised, the error would only be able to crash the server, not expose the data or put information at risk,” says Steve Manzuik, security product manager with eEye Research. “Basically, someone on the local network could crash the machine running the software. It doesn’t allow for any kind of actual access to the machine or to the data.” The Secunia Web site suggests until IBM readies patches that Tivoli Directory Server administrators restrict access to the LDAP service in the software and on the server. Because the flaw can only be exploited on the local network, Manzuik says the threat becomes even less critical, but still should be addressed.“It’s definitely something you should patch, but not something to patch out of your normal patch process,” he explains. “IBM is fairly responsive to flaws. Patching this for customers just depends on how quickly IBM can get the patch out.” Big Blue, which last year addressed a similar flaw with the directory software, reported it is working to develop and deliver fixes to the problem across the platforms it affects throughout February.An IBM spokeswoman says IBM is working to address the issue and is completing the fix. Not all platforms are affected, such as AIX. Fixes are estimated to be complete in February and available to customers and business partners. IBM will document and post to external Web sites and will send customer and business partners notifications with more details about the issue and where to obtain the fix, she says.There will also be ‘limited availability’ fixes available through product support. IBM says Tivoli Directory Server customers can get more information and suggested fixes here. Related content news Dell provides $150M to develop an AI compute cluster for Imbue Helping the startup build an independent system to create foundation models may help solidify Dell’s spot alongside cloud computing giants in the race to power AI. By Elizabeth Montalbano Nov 29, 2023 4 mins Generative AI news DRAM prices slide as the semiconductor industry starts to decline TSMC is reported to be cutting production runs on its mature process nodes as a glut of older chips in the market is putting downward pricing pressure on DDR4. By Sam Reynolds Nov 29, 2023 3 mins Flash Storage Technology Industry news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Cloud Computing opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe