First published: Sun Mar 16 2014(Updated: )
Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Information Analyzer | =8.5 | |
IBM InfoSphere Information Analyzer | =8.5.0.1 | |
IBM InfoSphere Information Analyzer | =8.5.0.2 | |
IBM InfoSphere Information Analyzer | =8.5.0.3 | |
IBM InfoSphere Information Analyzer | =8.7 | |
IBM InfoSphere Information Analyzer | =8.7.0.1 | |
IBM InfoSphere Information Analyzer | =8.7.0.2 | |
IBM InfoSphere Information Analyzer | =9.1 | |
IBM InfoSphere Information Analyzer | =9.1.0.1 | |
IBM InfoSphere Information Analyzer | =9.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4058 is classified as a critical vulnerability because it allows authenticated users to execute arbitrary SQL commands.
To mitigate CVE-2013-4058, update to the latest patched version of IBM InfoSphere Information Server provided by IBM.
CVE-2013-4058 affects IBM InfoSphere Information Server versions 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0.
CVE-2013-4058 can be exploited by remote authenticated users, making it a significant risk if user accounts are compromised.
SQL injection vulnerabilities, such as CVE-2013-4058, allow attackers to manipulate or execute database queries, potentially compromising data integrity and security.