CVE-2011-1366
Summary
| CVE | CVE-2011-1366 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-10-30 10:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in the Import feature in IBM Rational AppScan Enterprise and AppScan Reporting Console 5.2 through 7.9.x and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary commands on an agent server via a crafted ZIP archive. |
Risk And Classification
Primary CVSS: v2.0 8.8 from [email protected]
AV:N/AC:M/Au:N/C:N/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:N/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Rational Appscan | 5.2 | All | All | All |
| Application | Ibm | Rational Appscan | 5.2 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.4 | All | All | All |
| Application | Ibm | Rational Appscan | 5.4 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.5 | All | All | All |
| Application | Ibm | Rational Appscan | 5.5 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.5.0 | All | All | All |
| Application | Ibm | Rational Appscan | 5.5.0 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.5.0.1 | All | All | All |
| Application | Ibm | Rational Appscan | 5.5.0.1 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.5.0.2 | All | All | All |
| Application | Ibm | Rational Appscan | 5.5.0.2 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.6.0 | All | All | All |
| Application | Ibm | Rational Appscan | 5.6.0 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 5.6.0.3 | All | All | All |
| Application | Ibm | Rational Appscan | 5.6.0.3 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.7.0 | All | All | All |
| Application | Ibm | Rational Appscan | 7.7.0 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.7.0.1 | All | All | All |
| Application | Ibm | Rational Appscan | 7.7.0.1 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.7.0.2 | All | All | All |
| Application | Ibm | Rational Appscan | 7.7.0.2 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.8.0 | All | All | All |
| Application | Ibm | Rational Appscan | 7.8.0 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.8.0.1 | All | All | All |
| Application | Ibm | Rational Appscan | 7.8.0.1 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.8.0.2 | All | All | All |
| Application | Ibm | Rational Appscan | 7.8.0.2 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.9.0 | All | All | All |
| Application | Ibm | Rational Appscan | 7.9.0 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.9.0.1 | All | All | All |
| Application | Ibm | Rational Appscan | 7.9.0.1 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.9.0.2 | All | All | All |
| Application | Ibm | Rational Appscan | 7.9.0.2 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 7.9.0.3 | All | All | All |
| Application | Ibm | Rational Appscan | 7.9.0.3 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 8.0.0 | All | All | All |
| Application | Ibm | Rational Appscan | 8.0.0 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 8.0.0.1 | All | All | All |
| Application | Ibm | Rational Appscan | 8.0.0.1 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 8.0.0.2 | All | All | All |
| Application | Ibm | Rational Appscan | 8.0.0.2 | All | enterprise | All |
| Application | Ibm | Rational Appscan | 8.0.0.3 | All | All | All |
| Application | Ibm | Rational Appscan | 8.0.1 | All | enterprise | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: Vulnerability in Rational AppScan Standard, Express, Enterprise and Reporting Console with potential for command execution (CVE-2011-1366, CVE-2011-1367) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.