IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 configures a MySQL database to allow connections from any source IP address with the ns database account, which allows remote attackers to bypass the Netcool/NeuSecure application layer and perform unauthorized database actions. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/25270 | vdb entry |
http://www.securityfocus.com/archive/1/427155/100/0/threaded | mailing list |