IBM WebSphere Partner Gateway Console SQL Injection Vulnerability
BID:36058
Info
IBM WebSphere Partner Gateway Console SQL Injection Vulnerability
| Bugtraq ID: | 36058 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2093 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2009 12:00AM |
| Updated: | Aug 21 2009 03:48PM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Partner Gateway 6.1.1 .1 IBM WebSphere Partner Gateway 6.1.1 IBM WebSphere Partner Gateway 6.1 IBM WebSphere Partner Gateway 6.0 .7 IBM WebSphere Partner Gateway 6.0 .6 IBM WebSphere Partner Gateway 6.0 .5 IBM WebSphere Partner Gateway 6.0 .4 IBM WebSphere Partner Gateway 6.0 .3 IBM WebSphere Partner Gateway 6.0 .2 IBM WebSphere Partner Gateway 6.0 .1 IBM WebSphere Partner Gateway 6.0 IBM WebSphere Partner Gateway 6.2 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Partner Gateway Console SQL Injection Vulnerability
IBM WebSphere Partner Gateway is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The issue affects the following:
WebSphere Partner Gateway 6.0 Enterprise
WebSphere Partner Gateway 6.1.0 Enterprise
WebSphere Partner Gateway 6.1.1 Enterprise
WebSphere Partner Gateway 6.2 Enterprise
IBM WebSphere Partner Gateway is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
The issue affects the following:
WebSphere Partner Gateway 6.0 Enterprise
WebSphere Partner Gateway 6.1.0 Enterprise
WebSphere Partner Gateway 6.1.1 Enterprise
WebSphere Partner Gateway 6.2 Enterprise
Exploit / POC
IBM WebSphere Partner Gateway Console SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IBM WebSphere Partner Gateway Console SQL Injection Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
IBM WebSphere Partner Gateway Console SQL Injection Vulnerability
References:
References: