First published: Fri Jan 01 2016(Updated: )
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OpenPages | =7.0.0.0 | |
IBM OpenPages | =7.0.0.1 | |
IBM OpenPages | =7.0.0.2 | |
IBM OpenPages | =7.0.0.3 | |
IBM OpenPages | =7.0.0.4 | |
IBM OpenPages | =7.1.0.0 | |
IBM OpenPages | =7.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5049 is classified with a moderate severity level due to its ability to allow remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2015-5049, upgrade IBM OpenPages GRC Platform to version 7.0.0.4 IF3 or 7.1.0.1 IF6.
CVE-2015-5049 affects users of IBM OpenPages GRC Platform versions 7.0.0.0 through 7.1.0.0.
CVE-2015-5049 is an SQL injection vulnerability that affects the API of IBM OpenPages GRC Platform.
Yes, CVE-2015-5049 can be exploited remotely by authenticated users to run arbitrary SQL statements.