A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6980845 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/246320 | vdb entry vendor advisory |