PT-2009-5810 · Ibm · Ibm Rational Team Concert+2

Publicado

2009-10-01

·

Atualizado

2009-10-02

·

CVE-2009-3518

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Installation Manager versions 1.3.2 and earlier
Description The issue allows remote attackers to load arbitrary DLL files via the -vm option, potentially by referencing a UNC share pathname. This could be exploited in products that utilize IBM Installation Manager, such as IBM Rational Robot and Rational Team Concert.
Recommendations For IBM Installation Manager versions 1.3.2 and earlier, consider restricting access to the -vm option to prevent loading arbitrary DLL files until a patch is available. As a temporary workaround, avoid using the -vm option with UNC share pathnames to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3518

Produtos afetados

Ibm Installation Manager
Ibm Rational Robot
Ibm Rational Team Concert