Summary
This host has IBM Installation Manager installed and is prone to Argument Injection vulnerability.
Impact
Successful exploitation will allow attackers to execute arbitrary code or compromise a user's system.
Impact Level: Application/System
Solution
Upgrade to version 1.3.3 or later,
http://www-01.ibm.com/software/awdtools/installmanager/support
Insight
The flaw is due to error in 'IBMIM.exe' when handling arguments received via an 'iim:' URI. This can be exploited to load an arbitrary library from a network share via a specially crafted '-vm' argument.
Affected
IBM Installation Manager 1.3.2 and prior on Windows.
References
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2009-3518 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities