Lucene search

K
ibmIBMD68D4AE06D583577870A62D309D29D509AE341C0D60ED8290A97C2D344BC5BD3
HistorySep 25, 2022 - 8:45 p.m.

Security bulletin: Multiple vulnerabilities in IBM's Netezza WebAdmin 6.0.5, 6.0.8 and 7.0 (CVE-2012-5760, CVE-2012-5761, CVE-2012-5762, CVE-2012-5763, CVE-2012-5940, CVE-2012-5941)

2022-09-2520:45:36
www.ibm.com
11
ibm netezza
webadmin
cve-2012-5760
cve-2012-5761
cve-2012-5762
cve-2012-5763
cve-2012-5940
cve-2012-5941
sql commands
user input
mhtml protocol
ssl support

EPSS

0.002

Percentile

61.2%

Abstract

Multiple vulnerabilities have been identified in the IBM Netezza WebAdmin application.

Content

VULNERABILITY DETAILS:

CVE ID: CVE-2012-5760

DESCRIPTION:

Elements that could modify a SQL command are not neutralized correctly. The attack will not produce any visible outcome/output in the application but can potentially damage stored data.

CVSS:

CVSS Base Score: 6.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/80137 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVE ID: CVE-2012-5761

DESCRIPTION:

User controllable input is not correctly neutralized before it is placed in the output that is served as a web page permitting execution of untrusted scripts.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/80138 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5762

DESCRIPTION:

Internet Explorer can be forced to use MHTML protocol which can be manipulated to steal customer session and cookies.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/80204 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5763

DESCRIPTION:

The application may fail to verify the authenticity of requests and treat them all as valid. This can result in exposure of data or unintended code execution.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/80205 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5941

DESCRIPTION:

User controllable input is not correctly neutralized before it is placed in the output that is served as a web page permitting phishing attempts to steal private information.

CVSS:

CVSS Base Score: 3.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/80536 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVE ID: CVE-2012-5940

DESCRIPTION:

If SSL support is not enabled, login requests can be intercepted and the details accessed and/or stolen.

CVSS:

CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/80535 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N)

AFFECTED VERSIONS/PLATFORMS:

Versions 6.0.5, 6.0.8 and 7.0 of IBM Netezza WebAdmin.

REMEDIATION:

Fix(es):

Version 7.0: Install patch version 7.0 P2 which can be obtained via Fix Central
(http://www-933.ibm.com/support/fixcentral)

Workaround(s):

CVE-2012-5940: Install IBM Netezza WebAdmin 7.0 with SSL support.

Mitigation(s):

None known.

REFERENCES:

· Complete CVSS Guide
· On-line Calculator V2
· X-Force Vulnerability Database
· CVE-2012-5760
· CVE-2012-5761
· CVE-2012-5762
· CVE-2012-5763
· CVE-2012-5941
· CVE-2012-5940

RELATED INFORMATION:

· IBM Secure Engineering Web Portal
· IBM Product Security Incident Response Blog** **

_*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Flash. _

_Note: _According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an “industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.” IBM PROVIDES THE CVSS SCORES “AS IS” WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

[{“Product”:{“code”:“SSULQD”,“label”:“IBM PureData System”},“Business Unit”:{“code”:“BU053”,“label”:“Cloud \u0026 Data Platform”},“Component”:null,“Platform”:[{“code”:“PF025”,“label”:“Platform Independent”}],“Version”:“1.0.0”,“Edition”:“”,“Line of Business”:{“code”:“LOB10”,“label”:“Data and AI”}}]

EPSS

0.002

Percentile

61.2%

Related for D68D4AE06D583577870A62D309D29D509AE341C0D60ED8290A97C2D344BC5BD3