int(6346)

Vulnerability Bulletins


Vulnerabilidades en IBM System Storage

Vulnerability classification

Property Value
Confidence level Oficial
Impact Integridad
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer Comercial Software
Affected software IBM System Storage DS Storage Manager, versiones anteriores a la 10.83.xx.18

Description

Se han descubierto múltiples vulnerabilidades en IBM System Storage DS Storage Manager Profiler, incluido en IBM System Storage DS Series:

- [CVE-2012-2171] Vulnerabilidad de inyección SQL, que podría permitir a un atacante remoto con acceso al Storage Manager Profiler inyectar y ejecutar código SQL arbitrario.

- [CVE-2012-2172] Varias vulnerabilidades de tipo "cross-site scripting", que podrían permitir a un atacante remoto ejecutar código arbitrario en el navegador de una víctima.

Solution

Se recomienda aplicar el parche publicado por el fabricante, actualizando el producto a la última versión disponible.

Standar resources

Property Value
CVE CVE-2012-2171
CVE-2012-2172
BID

Other resources

Security Bulletin: IBM System Storage DS Storage Manager Profiler SQL Injection and Cross-Site Scripting Vulnerabilities (CVE-2012-2171, CVE-2012-2172)
https://www-304.ibm.com/connections/blogs/PSIRT/entry/secbulletin_stg-storage_cve-2012-2171_cve-2012-2172

Version history

Version Comments Date
1.0 Aviso emitido 2012-06-28