vendor:
IBM System Storage DS Storage Manager Profiler
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
SQL Injection and Cross-Site Scripting (XSS)
89, 79
CWE
Product Name: IBM System Storage DS Storage Manager Profiler
Affected Version From: 4.8.6
Affected Version To: 4.8.6
Patch Exists: YES
Related CWE: N/A
CPE: a:ibm:system_storage_ds_storage_manager_profiler
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache-Coyote/1.1, MySQL
2012
IBM System Storage DS Storage Manager Profiler Multiple Vulnerabilities
Input passed via the GET parameter 'selectedModuleOnly' in 'ModuleServlet.do' script is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. The GET parameter 'updateRegn' in the 'SoftwareRegistration.do' script is vulnerable to a XSS issue where the attacker can execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
Update to the latest version of IBM System Storage DS Storage Manager Profiler