Otkriven je nedostatak u radu proizvoda HP Operations Orchestration 9.x. Zlonamjerni korisnici mogu iskoristiti spomenuti propust za ubacivanje SQL koda i pokretanje proizvoljnog programskog koda.
HP Operations Orchestration RSScheduler Service SQL Injection Vulnerability
Secunia Advisory SA50413
Release Date 2012-08-30
Criticality level Moderately criticalModerately critical
Impact Manipulation of data
Where From local network
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Vendor Patch
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Software:
HP Operations Orchestration 9.x
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A vulnerability has been reported in HP Operations Orchestration, which can be exploited by malicious people to conduct SQL injection attacks.
Certain input passed to the RSScheduler service JDBC component is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
This can further be exploited to execute arbitrary code.
Solution
No official solution is currently available.
Provided and/or discovered by
Andrea Micalizzi aka rgod via ZDI.
Original Advisory
http://www.zerodayinitiative.com/advisories/ZDI-12-172/
Posljednje sigurnosne preporuke