Release date: 2011-10-07
Updated on: 2011-10-10
Affected Systems:
IBM Rational AppScan 8.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-1366, CVE-2011-1367
The Rational AppScan application security software can scan and test all common Web application vulnerabilities at various stages of development.
There are two security vulnerabilities in the implementation of IBM Rational AppScan, which can be exploited by malicious users to control user systems.
1) Unspecified details of the input function can be exploited through a specially crafted ZIP file;
2) unknown details in the file loading function can be exploited by specially crafted SCAN files;
<* Source: Secunia Research
Link: http://secunia.com/advisories/46326/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ers.ibm.com/