Release date:
Updated on: 2013-03-27
Affected Systems:
IBM Rational Policy Tester 8.x
IBM Rational Policy Tester 5.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2008-4033, CVE-2012-4431, CVE-2012-5081, CVE-2013-0473, CVE-2013-0474, CVE-2013-0511
IBM Rational Policy Tester is a leading automated online compliance solution that assesses compliance issues such as the quality, privacy, and accessibility of your enterprise Web assets.
Multiple vulnerabilities exist in IBM Rational Policy Tester 8.5-8.5.0.3, malicious users can exploit these vulnerabilities to execute SQL injection attacks, bypass security restrictions, execute cross-site scripting and request forgery attacks, and leak sensitive information.
<* Source: vendor
Link: http://secunia.com/advisories/52765/
Http://www-01.ibm.com/support/docview.wss? Uid = swg21631304
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ibm.com/support/fixcentral/