IBM Installation Manager "iim:" URI Remote Library Injection Vulnerability
RISK: Medium Risk
A vulnerability has been identified in IBM Installation Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "IBMIM.exe" file when processing parameters passed to the "-vm" argument via the "iim:" URI, which could allow attackers to load a malicious librairy from a remote location (e.g. network share) by tricking a user into visiting a specially crafted web page, leading to arbitrary code execution.
Impact
- Remote Code Execution
System / Technologies affected
IBM Installation Manager version 1.3.2 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to IBM Installation Manager version 1.3.3 :
http://www-01.ibm.com/support/docview.wss?rs=0&uid=swg21407330
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with