Unknown
CVE-2012-2171
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- ds storage manager host software,
- ds storage manager host software 10.60.x5.14,
- ds storage manager host software 10.8,
- ds4100,
- ds4100 1724,
- ds4200 1814,
- ds4300 1722,
- ds4400 1742,
- ds4500 1742,
- ds4700 1814,
- ds4800 1815,
- system storage dcs3700 storage subsystem 1818,
- system storage ds3200 1726,
- system storage ds3300 1726,
- system storage ds3400 1726,
- system storage ds3512 1746,
- system storage ds3524 1746,
- system storage ds3950 express 1814,
- system storage ds5020 disk controller 1814-20a,
- system storage ds5100 storage controller 1818,
- system storage ds5300 storage controller 1818
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: