IBM Tivoli Provisioning Manager TCP to ODBC Gateway Component SQL Injection Vulnerability
BID:43896
Info
IBM Tivoli Provisioning Manager TCP to ODBC Gateway Component SQL Injection Vulnerability
| Bugtraq ID: | 43896 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2010 12:00AM |
| Updated: | Oct 08 2010 12:00AM |
| Credit: | AbdulAziz Hariri |
| Vulnerable: |
IBM Tivoli Provisioning Manager for OS Deployment 5.1 3 Intirim Fix 3 IBM Tivoli Provisioning Manager for OS Deployment 5.1 .3 IBM Tivoli Provisioning Manager for OS Deployment 5.1 .116 IBM Tivoli Provisioning Manager for OS Deployment 5.1.Fix Pack 3 IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.2 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Provisioning Manager TCP to ODBC Gateway Component SQL Injection Vulnerability
IBM Tivoli Provisioning Manager is prone to a vulnerability that allows for the execution of arbitrary SQL commands.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
IBM Tivoli Provisioning Manager is prone to a vulnerability that allows for the execution of arbitrary SQL commands.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Exploit / POC
IBM Tivoli Provisioning Manager TCP to ODBC Gateway Component SQL Injection Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
IBM Tivoli Provisioning Manager TCP to ODBC Gateway Component SQL Injection Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
IBM Tivoli Provisioning Manager TCP to ODBC Gateway Component SQL Injection Vulnerability
References:
References: