PT-2009-5810 · Ibm · Ibm Rational Team Concert+2

Published

2009-10-01

·

Updated

2009-10-02

·

CVE-2009-3518

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Installation Manager versions 1.3.2 and earlier
Description The issue allows remote attackers to load arbitrary DLL files via the -vm option, potentially by referencing a UNC share pathname. This could be exploited in products that utilize IBM Installation Manager, such as IBM Rational Robot and Rational Team Concert.
Recommendations For IBM Installation Manager versions 1.3.2 and earlier, consider restricting access to the -vm option to prevent loading arbitrary DLL files until a patch is available. As a temporary workaround, avoid using the -vm option with UNC share pathnames to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3518

Affected Products

Ibm Installation Manager
Ibm Rational Robot
Ibm Rational Team Concert