First published: Fri Jan 07 2011(Updated: )
Multiple SQL injection vulnerabilities in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Collaborative Information Manager | <=8.0 | |
Tibco Activecatalog | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4496 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2010-4496, upgrade TIBCO Collaborative Information Manager to version 8.1.0 or later and TIBCO ActiveCatalog to version 1.0.1 or later.
CVE-2010-4496 affects TIBCO Collaborative Information Manager versions up to 8.0 and TIBCO ActiveCatalog versions up to 1.0.
CVE-2010-4496 is associated with multiple SQL injection vulnerabilities.
Yes, CVE-2010-4496 can be exploited remotely, allowing attackers to execute malicious SQL commands.