Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability
BID:47643
Info
Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability
| Bugtraq ID: | 47643 |
| Class: | Design Error |
| CVE: |
CVE-2011-1207 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2011 12:00AM |
| Updated: | Aug 18 2011 06:30PM |
| Credit: | Parvez Anwar via Secunia. |
| Vulnerable: |
Legacy Family Tree Legacy Family Tree 7.5.0.77 IBM Rational System Architect 11.4.0.0 IBM Rational System Architect 11.3.0.0 Data Dynamics ActiveBar ActiveX Control 1.0.6.5 |
| Not Vulnerable: |
IBM Rational System Architect 11.4.0.3 IBM Rational System Architect 11.3.1.4 |
Discussion
Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability
Data Dynamics ActiveBar ActiveX control is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the affected application (typically Internet Explorer) that uses the ActiveX control.
Data Dynamics ActiveBar 1.0.6.5 is vulnerable; other versions may also be affected.
Data Dynamics ActiveBar ActiveX control is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the affected application (typically Internet Explorer) that uses the ActiveX control.
Data Dynamics ActiveBar 1.0.6.5 is vulnerable; other versions may also be affected.
Exploit / POC
Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
Solution / Fix
Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
Data Dynamics ActiveBar ActiveX Control Insecure Method Vulnerability
References:
References:
- Data Dynamics Web Site (Data Dynamics)
- Microsoft Security Advisory 2562937 (Microsoft)
- Rational System Architect ActiveBar ActiveX Control Vulnerabilities (IBM)
- Vendor Homepage (Legacy Family Tree)
- Rational System Architect ActiveBar ActiveX Control Vulnerabilities (IBM)