CVE-2015-5049: SQL Injection
Published Jan 1, 2016
·Updated
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
7 affected components
IBM OpenPages GRC Platform=7.0.0.0
IBM OpenPages GRC Platform=7.0.0.1
IBM OpenPages GRC Platform=7.0.0.2
IBM OpenPages GRC Platform=7.0.0.3
IBM OpenPages GRC Platform=7.0.0.4
IBM OpenPages GRC Platform=7.1.0.0
IBM OpenPages GRC Platform=7.1.0.1
Event History
Jan 1, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5049?
CVE-2015-5049 is classified with a moderate severity level due to its ability to allow remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2015-5049?
To fix CVE-2015-5049, upgrade IBM OpenPages GRC Platform to version 7.0.0.4 IF3 or 7.1.0.1 IF6.
3
Who is affected by CVE-2015-5049?
CVE-2015-5049 affects users of IBM OpenPages GRC Platform versions 7.0.0.0 through 7.1.0.0.
4
What type of vulnerability is CVE-2015-5049?
CVE-2015-5049 is an SQL injection vulnerability that affects the API of IBM OpenPages GRC Platform.
5
Can CVE-2015-5049 be exploited remotely?
Yes, CVE-2015-5049 can be exploited remotely by authenticated users to run arbitrary SQL statements.