First published: Wed Apr 10 2019(Updated: )
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 154494.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Information Server On Cloud | =11.5 | |
Ibm Infosphere Information Server On Cloud | =11.7 | |
IBM InfoSphere Metadata Asset Manager | =11.5 | |
IBM InfoSphere Metadata Asset Manager | =11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1994 is critical.
IBM InfoSphere Information Server 11.5 and 11.7 becomes vulnerable to SQL injection when a remote attacker sends specially-crafted SQL statements.
A remote attacker can view, add, modify, or delete information in the back-end database if they exploit CVE-2018-1994.
Versions 11.5 and 11.7 of IBM InfoSphere Information Server are affected by CVE-2018-1994.
To fix the SQL injection vulnerability in IBM InfoSphere Information Server, apply the necessary security patches provided by IBM.