First published: Fri Jun 22 2012(Updated: )
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Ds Storage Manager Host Software | <=10.83 | |
Ibm Ds Storage Manager Host Software | =10.8 | |
Ibm Ds Storage Manager Host Software | =10.60.x5.14 | |
IBM DS4100 | ||
IBM DS4100 | =1724 | |
Ibm Ds4200 | =1814 | |
Ibm Ds4300 | =1722 | |
Ibm Ds4400 | =1742 | |
Ibm Ds4500 | =1742 | |
Ibm Ds4700 | =1814 | |
Ibm Ds4800 | =1815 | |
Ibm System Storage Dcs3700 Storage Subsystem | =1818 | |
Ibm System Storage Ds3200 | =1726 | |
Ibm System Storage Ds3300 | =1726 | |
Ibm System Storage Ds3400 | =1726 | |
Ibm System Storage Ds3512 | =1746 | |
Ibm System Storage Ds3524 | =1746 | |
Ibm System Storage Ds3950 Express | =1814 | |
Ibm System Storage Ds5020 Disk Controller | =1814-20a | |
Ibm System Storage Ds5100 Storage Controller | =1818 | |
Ibm System Storage Ds5300 Storage Controller | =1818 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.