Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Vulnerabilities
BID:52248
Info
Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 52248 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-0198 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2012 12:00AM |
| Updated: | Mar 01 2012 12:00AM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 |
| Not Vulnerable: | |
Discussion
Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Vulnerabilities
IBM Tivoli Provisioning Manager Express for Software Distribution is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data such as the SHA1 160 bits encrypted admin password and update account rights, or exploit vulnerabilities in the underlying database.
IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 is vulnerable.
IBM Tivoli Provisioning Manager Express for Software Distribution is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data such as the SHA1 160 bits encrypted admin password and update account rights, or exploit vulnerabilities in the underlying database.
IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 is vulnerable.
Solution / Fix
Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Tivoli Provisioning Manager Express for Software Distribution Multiple SQL Injection Vulnerabilities
References:
References: