IBM InfoSphere Optim Solutions CVE-2013-2956 Unspecified SQL Injection Vulnerabilitiy
BID:59842
Info
IBM InfoSphere Optim Solutions CVE-2013-2956 Unspecified SQL Injection Vulnerabilitiy
| Bugtraq ID: | 59842 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2956 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2013 12:00AM |
| Updated: | May 13 2013 12:00AM |
| Credit: | Reported by vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Optim Solutions CVE-2013-2956 Unspecified SQL Injection Vulnerabilitiy
IBM InfoSphere Optim Data Growth Solution for Oracle E-Business Suite is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
IBM InfoSphere Optim Data Growth Solution for Oracle E-Business Suite versions 6.0 through 9.1 are vulnerable.
IBM InfoSphere Optim Data Growth Solution for Oracle E-Business Suite is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database
IBM InfoSphere Optim Data Growth Solution for Oracle E-Business Suite versions 6.0 through 9.1 are vulnerable.
Exploit / POC
IBM InfoSphere Optim Solutions CVE-2013-2956 Unspecified SQL Injection Vulnerabilitiy
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
IBM InfoSphere Optim Solutions CVE-2013-2956 Unspecified SQL Injection Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM InfoSphere Optim Solutions CVE-2013-2956 Unspecified SQL Injection Vulnerabilitiy
References:
References:
- IBM Homepage (IBM)