QID 378789

QID 378789: IBM Spectrum Control XML Injection vulnerability (6959029)

Vulnerability in dom4j allows remote attacker to execute arbitrary code on the system may affect IBM Spectrum Control.

Affected Versions:
IBM Spectrum Protect 5.4.0 to 5.4.9

QID Detection Logic(Authenticated):
It checks for vulnerable version of IBM Spectrum Control version from version.txt under installation path in windows.

dom4j could allow a remote attacker to execute arbitrary code on the system, caused by improper input validation in multiple methods. By sending a specially-crafted XML content, an attacker could exploit this vulnerability to execute arbitrary code on the system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released updated version to address this issue. Refer to ibm6261327 for details.
    Vendor References

    CVEs related to QID 378789

    Software Advisories
    Advisory ID Software Component Link
    6959029 URL Logo www.ibm.com/support/pages/node/6959029