First published: Thu Oct 28 2010(Updated: )
Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL commands via (1) the rdReport parameter to rdpageimlogic.aspx, related to the sGetDefinition function in rdServer.dll, and SQL statements contained within a certain report file; (2) unspecified parameters in a DetailReportGroup (aka DetailReportGroup.lgx) action to rdpageimlogic.aspx; the (3) selclause, (4) whereTrendTimeClause, (5) TrendTypeForReport, (6) whereProtocolClause, or (7) groupClause parameter in a SummaryReportGroup (aka SummaryReportGroup.lgx) action to rdpageimlogic.aspx; the (8) loginTimeStamp, (9) dbo, (10) dateDiffParam, or (11) whereClause parameter in a LoggedInUsers (aka LoggedInUSers.lgx) action to (a) rdpageimlogic.aspx or (b) rdPage.aspx; the (12) selclause, (13) whereTrendTimeClause, (14) TrendTypeForReport, (15) whereProtocolClause, or (16) groupClause parameter to rdpageimlogic.aspx; (17) the groupList parameter to IMAdminReportTrendFormRun.asp; or (18) the email parameter to IMAdminScheduleReport.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Identity Manager | <=8.4.15 | |
Symantec Identity Manager | =6.0 | |
Symantec Identity Manager | =6.5 | |
Symantec Identity Manager | =7.0 | |
Symantec Identity Manager | =7.5 | |
Symantec Identity Manager | =8.3 | |
Symantec Identity Manager | =8.4.0 | |
Symantec Identity Manager | =8.4.1 | |
Symantec Identity Manager | =8.4.2 | |
Symantec Identity Manager | =8.4.5 | |
Symantec Identity Manager | =8.4.6 | |
Symantec Identity Manager | =8.4.7 | |
Symantec Identity Manager | =8.4.8 | |
Symantec Identity Manager | =8.4.9 | |
Symantec Identity Manager | =8.4.10 | |
Symantec Identity Manager | =8.4.11 | |
Symantec Identity Manager | =8.4.12 | |
Symantec Identity Manager | =8.4.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0112 is classified as a high severity vulnerability due to the possibility of remote SQL injection leading to arbitrary command execution.
To fix CVE-2010-0112, upgrade Symantec IM Manager to version 8.4.16 or later to mitigate the SQL injection vulnerabilities.
CVE-2010-0112 affects multiple versions of Symantec IM Manager, specifically versions prior to 8.4.16 and several specific versions from 6.0 to 8.4.13.
Attackers can exploit CVE-2010-0112 to perform SQL injection attacks, potentially allowing them to manipulate the database and gain unauthorized access.
The vulnerability in CVE-2010-0112 is primarily associated with the rdReport parameter in the rdpageimlogic.aspx file.