IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21989205 | patch vendor advisory |
http://www.securityfocus.com/bid/93076 | vdb entry |