Vulnerability Bulletins |
Vulnerabilidades en IBM System Storage |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Integridad |
| Dificulty | Avanzado |
| Required attacker level | Acceso remoto sin cuenta a un servicio exotico |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software | IBM System Storage DS Storage Manager, versiones anteriores a la 10.83.xx.18 |
Description |
|
|
Se han descubierto múltiples vulnerabilidades en IBM System Storage DS Storage Manager Profiler, incluido en IBM System Storage DS Series: - [CVE-2012-2171] Vulnerabilidad de inyección SQL, que podría permitir a un atacante remoto con acceso al Storage Manager Profiler inyectar y ejecutar código SQL arbitrario. - [CVE-2012-2172] Varias vulnerabilidades de tipo "cross-site scripting", que podrían permitir a un atacante remoto ejecutar código arbitrario en el navegador de una víctima. |
|
Solution |
|
| Se recomienda aplicar el parche publicado por el fabricante, actualizando el producto a la última versión disponible. | |
Standar resources |
|
| Property | Value |
| CVE |
CVE-2012-2171 CVE-2012-2172 |
| BID | |
Other resources |
|
|
Security Bulletin: IBM System Storage DS Storage Manager Profiler SQL Injection and Cross-Site Scripting Vulnerabilities (CVE-2012-2171, CVE-2012-2172) https://www-304.ibm.com/connections/blogs/PSIRT/entry/secbulletin_stg-storage_cve-2012-2171_cve-2012-2172 |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2012-06-28 |






