Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-1560

28
FAUCET Score

CVE-2011-1560 describes a critical authentication bypass vulnerability in IBM solidDB versions prior to 4.5.181, 6.0.1067, 6.3.47, and 6.5.0.3. The flaw allows remote attackers to bypass authentication by manipulating the password-hash length during client-server communication. With a CVSS score of 9.3, this vulnerability presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability due to its network-based attack vector and low attack complexity. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.5.180CPE matchmatch criteria
cpe:2.3:a:ibm:soliddb:*:*:*:*:*:*:*:*
4.5.167CPE matchmatch criteria
cpe:2.3:a:ibm:soliddb:4.5.167:*:*:*:*:*:*:*
4.5.168CPE matchmatch criteria
cpe:2.3:a:ibm:soliddb:4.5.168:*:*:*:*:*:*:*
4.5.169CPE matchmatch criteria
cpe:2.3:a:ibm:soliddb:4.5.169:*:*:*:*:*:*:*
4.5.173CPE matchmatch criteria
cpe:2.3:a:ibm:soliddb:4.5.173:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
3.99%
Probability of exploitation in next 30 days
EPSS Percentile
89.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0399 is in the 52nd percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

fuji_electricvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
lizardbytevendor investigatingvia llm_extracted
opensipsvendor investigatingvia llm_extracted

Vendor Advisories (4)

langgeniusllm-langgenius-b9e45723de936964HIGH

IBM solidDB Password Hash Verification Bypass Remote Code Execution

Apr 1, 2011
lizardbytellm-lizardbyte-60f4556150588490HIGH

IBM solidDB Password Hash Verification Bypass Remote Code Execution

Apr 1, 2011
opensipsllm-opensips-cc0698f8ffe635fcHIGH

IBM solidDB Password Hash Verification Bypass Remote Code Execution

Apr 1, 2011
fuji_electricllm-fuji_electric-4fc5af9f74108c8fHIGH

IBM solidDB Password Hash Verification Bypass Remote Code Execution

Apr 1, 2011

References

osvdb.org / 71494
secunia.com / advisories/44030
exchange.xforce.ibmcloud.com / vulnerabilities/66455
ibm.com / support/docview.wss
Vendor Advisory
vupen.com / english/advisories/2011/0854
zerodayinitiative.com / advisories/ZDI-11-115