First published: Fri Dec 23 2011(Updated: )
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the InsertMarker method, which allows remote attackers to execute arbitrary code via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
.bbsoftware Bb Flashback | ||
IBM Rational Rhapsody | <=7.6.0.1 | |
IBM Rational Rhapsody | =7.5 | |
IBM Rational Rhapsody | =7.5.0.1 | |
IBM Rational Rhapsody | =7.5.1 | |
IBM Rational Rhapsody | =7.5.1.1 | |
IBM Rational Rhapsody | =7.5.2 | |
IBM Rational Rhapsody | =7.5.2.1 | |
IBM Rational Rhapsody | =7.5.3 | |
IBM Rational Rhapsody | =7.5.3.1 | |
IBM Rational Rhapsody | =7.5.3.2 | |
IBM Rational Rhapsody | =7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1391 is classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2011-1391, update to the latest version of Blueberry BB FlashBack or IBM Rational Rhapsody where the vulnerability is patched.
CVE-2011-1391 affects Blueberry BB FlashBack and IBM Rational Rhapsody versions prior to 7.6.1.
Yes, exploitation of CVE-2011-1391 can potentially lead to unauthorized access and data loss.
If using a vulnerable version linked to CVE-2011-1391, it is recommended to immediately update to the latest secure version.