LPAR2RRD Command Injection Vulnerability (CVE-2014-4982)
Release date:
Updated on:
Affected Systems:
LPAR2RRD LPAR2RRD <= 4.53
LPAR2RRD LPAR2RRD <= 3.5
Unaffected system:
LPAR2RRD LPAR2RRD> 4.53
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68850
CVE (CAN) ID: CVE-2014-4982
LPAR2RRD is the performance monitoring and capacity planning software for IBM Power Systems devices.
LPAR2RRD <= 4.53, <= 3.5 does not effectively filter parameter values in the Application Web GUI, which can cause arbitrary commands to be injected into the application server.
<* Source: J & #195; & #188; rgen Bilberger
Link: http://www.securityfocus.com/archive/1/532866
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
LPAR2RRD
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.lpar2rrd.com
This article permanently updates the link address: