HTTP: IBM Tivoli Provisioning Manager Express User.updateUserValue SQL Injection
This signature detects attempts to exploit a known vulnerability in IBM Tivoli Provisioning Manager. It is due to insufficient validation of user-supplied input. An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
Extended Description
IBM Tivoli Provisioning Manager Express for Software Distribution is prone to a remote code-execution vulnerability. An attacker could exploit this issue to write arbitrary data to a local file and execute that data in the context of the application using the affected control (typically Internet Explorer). IBM Tivoli Provisioning Manager Express for Software Distribution 4.1.1 is vulnerable.
Affected Products
Ibm tivoli_provisioning_manager_express_for_software_distribution
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Ibm
7.5