IBM InfoSphere Information Server CVE-2018-1994 SQL Injection Vulnerability
BID:107891
Info
IBM InfoSphere Information Server CVE-2018-1994 SQL Injection Vulnerability
| Bugtraq ID: | 107891 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1994 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2019 12:00AM |
| Updated: | Jan 30 2019 12:00AM |
| Credit: | Pawel Gocyla. |
| Vulnerable: |
IBM InfoSphere Metadata Asset Manager 11.7 IBM InfoSphere Metadata Asset Manager 11.5 IBM InfoSphere Information Server on Cloud 11.7 IBM InfoSphere Information Server on Cloud 11.5 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Information Server CVE-2018-1994 SQL Injection Vulnerability
IBM InfoSphere Information Server is prone to a SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
IBM InfoSphere Metadata Asset Manager versions 11.5, and 11.7
IBM InfoSphere Information Server on Cloud versions 11.5, and 11.7
IBM InfoSphere Information Server is prone to a SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The following products are affected:
IBM InfoSphere Metadata Asset Manager versions 11.5, and 11.7
IBM InfoSphere Information Server on Cloud versions 11.5, and 11.7
References
IBM InfoSphere Information Server CVE-2018-1994 SQL Injection Vulnerability
References:
References: