IBM IMS Enterprise Suite SOAP Gateway CVE-2013-3003 Local Arbitrary Command Execution Vulnerability
BID:60891
Info
IBM IMS Enterprise Suite SOAP Gateway CVE-2013-3003 Local Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 60891 |
| Class: | Design Error |
| CVE: |
CVE-2013-3003 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 02 2013 12:00AM |
| Updated: | Jul 02 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM IMS 10 |
| Not Vulnerable: | |
Discussion
IBM IMS Enterprise Suite SOAP Gateway CVE-2013-3003 Local Arbitrary Command Execution Vulnerability
IBM IMS Enterprise Suite SOAP Gateway is prone to a local arbitrary command-execution vulnerability.
Local attackers can exploit this issue to execute arbitrary commands with the privileges of the authenticated user. This may facilitate a complete compromise of an affected application.
The following versions are affected:
IBM IMS Enterprise Suite 1.1
IBM IMS Enterprise Suite 2.1
IBM IMS Enterprise Suite 2.2
IBM IMS Enterprise Suite SOAP Gateway is prone to a local arbitrary command-execution vulnerability.
Local attackers can exploit this issue to execute arbitrary commands with the privileges of the authenticated user. This may facilitate a complete compromise of an affected application.
The following versions are affected:
IBM IMS Enterprise Suite 1.1
IBM IMS Enterprise Suite 2.1
IBM IMS Enterprise Suite 2.2
Exploit / POC
IBM IMS Enterprise Suite SOAP Gateway CVE-2013-3003 Local Arbitrary Command Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM IMS Enterprise Suite SOAP Gateway CVE-2013-3003 Local Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM IMS Enterprise Suite SOAP Gateway CVE-2013-3003 Local Arbitrary Command Execution Vulnerability
References:
References:
- IBM Homepage (IBM)