SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ibm
Subscribe
|
Ds4100
Subscribe
Ds4200
Subscribe
Ds4300
Subscribe
Ds4400
Subscribe
Ds4500
Subscribe
Ds4700
Subscribe
Ds4800
Subscribe
Ds Storage Manager Host Software
Subscribe
System Storage Dcs3700 Storage Subsystem
Subscribe
System Storage Ds3200
Subscribe
System Storage Ds3300
Subscribe
System Storage Ds3400
Subscribe
System Storage Ds3512
Subscribe
System Storage Ds3524
Subscribe
System Storage Ds3950 Express
Subscribe
System Storage Ds5020 Disk Controller
Subscribe
System Storage Ds5100 Storage Controller
Subscribe
System Storage Ds5300 Storage Controller
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-2165 | SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-06T19:26:08.463Z
Reserved: 2012-04-04T00:00:00
Link: CVE-2012-2171
No data.
Status : Deferred
Published: 2012-06-22T10:24:06.957
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-2171
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD