IBM InfoSphere Information Server Multiple Security Vulnerabilities
BID:57635
Info
IBM InfoSphere Information Server Multiple Security Vulnerabilities
| Bugtraq ID: | 57635 |
| Class: | Unknown |
| CVE: |
CVE-2012-0203 CVE-2012-0204 CVE-2012-0205 CVE-2012-0700 CVE-2012-0701 CVE-2012-0702 CVE-2012-0703 CVE-2012-0705 CVE-2012-4819 CVE-2012-4832 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2013 12:00AM |
| Updated: | Jun 13 2014 05:14PM |
| Credit: | Vendor reported these issues. |
| Vulnerable: |
IBM InfoSphere Information Server 8.5 IBM InfoSphere Information Server 8.1 IBM InfoSphere Information Server 8.0 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Information Server Multiple Security Vulnerabilities
Moodle is prone to multiple security vulnerabilities, including:
1. A security-bypass vulnerability
2. Local unauthorized access vulnerability
3. Local information-disclosure vulnerability
4. Multiple remote command-execution vulnerabilities
5. Multiple remote privilege escalation vulnerabilities
6. Multiple cross-site scripting vulnerabilities
7. An open-redirection vulnerability
Attackers can exploit these issues to steal cookie-based authentication information, execute arbitrary scripts in the context of the browser, bypass certain security restrictions, gain unauthorized access, obtain sensitive information, execute arbitrary code in context of the user running the application, gain elevated privileges, and conduct phishing attacks. Other attacks may also be possible.
IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 are vulnerable.
Moodle is prone to multiple security vulnerabilities, including:
1. A security-bypass vulnerability
2. Local unauthorized access vulnerability
3. Local information-disclosure vulnerability
4. Multiple remote command-execution vulnerabilities
5. Multiple remote privilege escalation vulnerabilities
6. Multiple cross-site scripting vulnerabilities
7. An open-redirection vulnerability
Attackers can exploit these issues to steal cookie-based authentication information, execute arbitrary scripts in the context of the browser, bypass certain security restrictions, gain unauthorized access, obtain sensitive information, execute arbitrary code in context of the user running the application, gain elevated privileges, and conduct phishing attacks. Other attacks may also be possible.
IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 are vulnerable.
Exploit / POC
IBM InfoSphere Information Server Multiple Security Vulnerabilities
An attacker can use a browser to exploit some of these issues.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker can use a browser to exploit some of these issues.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM InfoSphere Information Server Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM InfoSphere Information Server Multiple Security Vulnerabilities
References:
References: