First published: Thu Jan 31 2013(Updated: )
InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Analyzer | =8.1 | |
IBM InfoSphere Information Analyzer | =8.5 | |
IBM InfoSphere Information Analyzer | =8.5.0.1 | |
IBM InfoSphere Information Analyzer | =8.5.0.2 | |
IBM InfoSphere Information Analyzer | =8.7 | |
IBM InfoSphere Information Analyzer | =9.1 | |
IBM InfoSphere Information Server MetaBrokers & Bridges |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0705 is rated as a critical severity vulnerability due to the potential for remote command execution.
To fix CVE-2012-0705, users should update to the appropriate fix pack for their version of IBM InfoSphere Information Server as recommended by IBM.
CVE-2012-0705 affects IBM InfoSphere Information Server versions 8.1, 8.5 before FP3, 8.7, and 9.1.
CVE-2012-0705 can be exploited by remote authenticated users who can send specially crafted input data.
Currently, the best practice is to apply the security updates provided by IBM for CVE-2012-0705 without known workarounds.