IBM InfoSphere Information Server CVE-2013-4058 Unspecified SQL Injection Vulnerabilitiy
BID:66155
Info
IBM InfoSphere Information Server CVE-2013-4058 Unspecified SQL Injection Vulnerabilitiy
| Bugtraq ID: | 66155 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4058 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2014 12:00AM |
| Updated: | Aug 21 2014 12:33PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Information Server CVE-2013-4058 Unspecified SQL Injection Vulnerabilitiy
IBM InfoSphere Information Server is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 are vulnerable; other versions may also be affected.
IBM InfoSphere Information Server is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 are vulnerable; other versions may also be affected.
Exploit / POC
IBM InfoSphere Information Server CVE-2013-4058 Unspecified SQL Injection Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IBM InfoSphere Information Server CVE-2013-4058 Unspecified SQL Injection Vulnerabilitiy
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM InfoSphere Information Server CVE-2013-4058 Unspecified SQL Injection Vulnerabilitiy
References:
References:
- IBM Homepage (IBM)
- IBM InfoSphere Information Server (IBM)