CVE-2014-0966: SQL Injection
SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0966?
CVE-2014-0966 is classified as a critical severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2014-0966?
The recommended fix for CVE-2014-0966 is to upgrade to the fixed versions of IBM InfoSphere Master Data Management, specifically version 11.0-FP5 or later.
Who is affected by CVE-2014-0966?
CVE-2014-0966 affects remote authenticated users of IBM InfoSphere Master Data Management and its Collaborative Edition across several versions.
What type of vulnerability is CVE-2014-0966?
CVE-2014-0966 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
When was CVE-2014-0966 reported?
CVE-2014-0966 was reported in 2014 as part of a broader set of vulnerabilities affecting IBM's software.