IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89257 | vendor advisory broken link |
http://www-01.ibm.com/support/docview.wss?uid=swg21990317 | vendor advisory |
http://www.securityfocus.com/bid/93176 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89322 | vendor advisory broken link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89326 | vendor advisory broken link |