IBM Tivoli Provisioning Manager SQL Injection

Strike ID:
E12-35j01
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
1
Year:
2012

Description

This strike exploits an SQL Injection in IBM Tivoli Provisioning Manager where an attacker can update underlying data. In particular, a user may upgrade their account to an administrator.

CVE