IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21985748 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/111302 | vdb entry vendor advisory |