Release date:
Updated on:
Affected Systems:
IBM DS4700
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54112
CVE (CAN) ID: CVE-2012-2171
IBM System Storage is a solution that reduces System Storage complexity and improves the performance of enterprise Storage hardware, software, and services.
ModuleServlet in Storage Manager Profiler in IBM System Storage DS Storage Manager 10.83.xx.18 on DS devices. do has the SQL injection vulnerability. You can remotely inject SQL commands by acting on the selectedModuleOnly parameter in state_viewmodulelog of ModuleServlet URI.
<* Source: Gjoko Krstic (liquidworm@gmail.com)
Link: http://secunia.com/advisories/49582/
Http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5094.php
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
XSS:
Http://www.example.com/SoftwareRegistration.do? UpdateRegn = "& gt; & lt; script & gt; alert (1); & lt;/script & gt;
SQL Injection:
Http://www.example.com/ModuleServlet? DeviceId = 1 & amp; state = state_viewmodulelog & amp; selectedModuleOnly = 1 [SQL QUERY] & amp; selectedModule = 1
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/