Short Name |
HTTP:SQL:INJ:TIVOLI-USER-UPDATE |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
IBM Tivoli Provisioning Manager Express User.updateUserValue SQL Injection |
Release Date |
2013/01/09 |
Update Number |
2223 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in IBM Tivoli Provisioning Manager. It is due to insufficient validation of user-supplied input. An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
IBM Tivoli Provisioning Manager Express for Software Distribution is prone to a remote code-execution vulnerability. An attacker could exploit this issue to write arbitrary data to a local file and execute that data in the context of the application using the affected control (typically Internet Explorer). IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 is vulnerable.