Boletines de Vulnerabilidades

IBM Security Bulletin: InstallAnywhere generates installation executables which are vulnerable to a DLL-planting vulnerability (CVE-2016-4560)

   
Software afectado IBM
 
Flexera InstallAnywhere, shipped and used by IBM Spectrum Control and Tivoli Storage Productivity Center, could allow a local attacker to gain elevated privileges on the system by using a Trojan horse DLL in the current working directory of a setup-launcher.CVE(s): CVE-2016-4560Affected product(s) and affected version(s):IBM Spectrum Control 5.2.8 through 5.2.9 (Windows) Tivoli Storage Productivity Center 5.2.0 through 5.2.7 (Windows) Tivoli Storage Productivity Center 5.1.0 through 5.1.1.9

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-installanywhere-generates-installation-executables-which-are-vulnerable-to-a-dll-planting-vulnerability-cve-2016-4560/