Short Name |
HTTP:STC:ACTIVEX:IBM-TIVOLI |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
IBM Tivoli Provisioning Manager Express ActiveX |
Release Date |
2012/04/09 |
Update Number |
2113 |
Supported Platforms |
idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to use unsafe ActiveX controls in the IBM Tivoli Provisioning Manager Express Component. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.
IBM Tivoli Provisioning Manager Express for Software Distribution is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data such as the SHA1 160 bits encrypted admin password and update account rights, or exploit vulnerabilities in the underlying database. IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 is vulnerable.