CVE-2013-2974: SQL Injection
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2974?
CVE-2013-2974 is considered a high severity vulnerability due to the potential for unauthorized report administration and SQL injection.
How do I fix CVE-2013-2974?
To fix CVE-2013-2974, upgrade your IBM Tivoli Application Dependency Discovery Manager to version 7.2.1.5 or later.
Who is affected by CVE-2013-2974?
CVE-2013-2974 affects users of IBM Tivoli Application Dependency Discovery Manager versions 7.2.1.1 to 7.2.1.4.
What kind of attacks can be executed due to CVE-2013-2974?
CVE-2013-2974 allows attackers to create or delete reports and conduct SQL injection attacks.
Is user authentication required to exploit CVE-2013-2974?
Yes, CVE-2013-2974 requires remote authenticated users to exploit the vulnerability.