First published: Fri Jun 22 2012(Updated: )
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DS Storage Manager Host Software | <=10.83 | |
IBM DS Storage Manager Host Software | =10.8 | |
IBM DS Storage Manager Host Software | =10.60.x5.14 | |
IBM DS4100 | ||
IBM DS4100 | =1724 | |
IBM DS4200 | =1814 | |
IBM DS4300 | =1722 | |
IBM DS4400 | =1742 | |
IBM DS4500 | =1742 | |
IBM DS4700 | =1814 | |
IBM DS4800 | =1815 | |
IBM System Storage DCS3700 Storage Subsystem | =1818 | |
IBM System Storage DS3200 | =1726 | |
IBM System Storage DS3300 | =1726 | |
IBM System Storage DS3400 | =1726 | |
IBM System Storage DS3512 | =1746 | |
IBM System Storage DS3524 | =1746 | |
IBM System Storage DS3950 Express | =1814 | |
IBM System Storage DS5020 Disk Controller | =1814-20a | |
IBM System Storage DS5100 Storage Controller | =1818 | |
IBM System Storage DS5300 Storage Controller | =1818 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2171 has a medium severity rating due to its potential for SQL injection exploits.
To mitigate CVE-2012-2171, it is recommended to upgrade the IBM System Storage DS Storage Manager to a version above 10.83.xx.18.
CVE-2012-2171 affects remote authenticated users of IBM System Storage DS Storage Manager versions prior to 10.83.xx.18.
CVE-2012-2171 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
CVE-2012-2171 was disclosed in June 2012.