CVE-2011-1391: Code Injection
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the InsertMarker method, which allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1391?
CVE-2011-1391 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2011-1391?
To mitigate CVE-2011-1391, update to the latest version of Blueberry BB FlashBack or IBM Rational Rhapsody where the vulnerability is patched.
What products are affected by CVE-2011-1391?
CVE-2011-1391 affects Blueberry BB FlashBack and IBM Rational Rhapsody versions prior to 7.6.1.
Can CVE-2011-1391 lead to data loss?
Yes, exploitation of CVE-2011-1391 can potentially lead to unauthorized access and data loss.
What actions should I take if I'm using a vulnerable version related to CVE-2011-1391?
If using a vulnerable version linked to CVE-2011-1391, it is recommended to immediately update to the latest secure version.