Microsoft BizTalk Server DTA Interface SQL Injection Vulnerability
BID:7470
Info
Microsoft BizTalk Server DTA Interface SQL Injection Vulnerability
| Bugtraq ID: | 7470 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0118 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2003 12:00AM |
| Updated: | Jul 11 2009 09:07PM |
| Credit: | Discovery credited to Cesar Cerrudo. |
| Vulnerable: |
Microsoft BizTalk Server 2002 Enterprise Edition Microsoft BizTalk Server 2002 Developer Edition Microsoft BizTalk Server 2000 Standard Edition SP2 Microsoft BizTalk Server 2000 Standard Edition SP1a Microsoft BizTalk Server 2000 Standard Edition Microsoft BizTalk Server 2000 Enterprise Edition SP2 Microsoft BizTalk Server 2000 Enterprise Edition SP1a Microsoft BizTalk Server 2000 Enterprise Edition Microsoft BizTalk Server 2000 Developer Edition SP2 Microsoft BizTalk Server 2000 Developer Edition SP1a Microsoft BizTalk Server 2000 Developer Edition |
| Not Vulnerable: | |
Discussion
Microsoft BizTalk Server DTA Interface SQL Injection Vulnerability
A vulnerability has been reported for BizTalk Server which may make it possible for remote users to modify database query logic. The vulnerability exists in some of the pages used by the DTA interface.
This vulnerability may be the result of inadequate sanitization of user-supplied values for some parameters. A remote attacker may exploit this vulnerability by creating a malicious URL that includes specially crafted SQL queries to execute commands or compromise the database.
A vulnerability has been reported for BizTalk Server which may make it possible for remote users to modify database query logic. The vulnerability exists in some of the pages used by the DTA interface.
This vulnerability may be the result of inadequate sanitization of user-supplied values for some parameters. A remote attacker may exploit this vulnerability by creating a malicious URL that includes specially crafted SQL queries to execute commands or compromise the database.
Solution / Fix
Microsoft BizTalk Server DTA Interface SQL Injection Vulnerability
Solution:
Microsoft has released patches to address this issue:
Microsoft BizTalk Server 2000 Developer Edition
Microsoft BizTalk Server 2000 Developer Edition SP1a
Microsoft BizTalk Server 2000 Enterprise Edition SP1a
Microsoft BizTalk Server 2000 Standard Edition SP2
Microsoft BizTalk Server 2002 Developer Edition
Microsoft BizTalk Server 2000 Enterprise Edition SP2
Microsoft BizTalk Server 2000 Enterprise Edition
Microsoft BizTalk Server 2000 Developer Edition SP2
Microsoft BizTalk Server 2002 Enterprise Edition
Microsoft BizTalk Server 2000 Standard Edition SP1a
Microsoft BizTalk Server 2000 Standard Edition
Solution:
Microsoft has released patches to address this issue:
Microsoft BizTalk Server 2000 Developer Edition
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2000 Developer Edition SP1a
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2000 Enterprise Edition SP1a
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2000 Standard Edition SP2
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2002 Developer Edition
-
Microsoft BTS2002-815208
http://microsoft.com/downloads/details.aspx?FamilyId=A05344FE-2622-488 7-AA45-3DE7C4ED3C75&displaylang=en
Microsoft BizTalk Server 2000 Enterprise Edition SP2
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2000 Enterprise Edition
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2000 Developer Edition SP2
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2002 Enterprise Edition
-
Microsoft BTS2002-815208
http://microsoft.com/downloads/details.aspx?FamilyId=A05344FE-2622-488 7-AA45-3DE7C4ED3C75&displaylang=en
Microsoft BizTalk Server 2000 Standard Edition SP1a
-
Microsoft BTS2000-815207
http://microsoft.com/downloads/details.aspx?FamilyId=001E93E4-0E6E-428 9-AEFE-9161D2E5AF97&displaylang=en
Microsoft BizTalk Server 2000 Standard Edition
References
Microsoft BizTalk Server DTA Interface SQL Injection Vulnerability
References:
References: