IBM Raditional Appscan Products Two Vulnerabilities
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
Two vulnerabilities have been identified in IBM Rational AppScan, which can be exploited by malicious people to compromise a user's system.
An unspecified error in the import functionality can be exploited via a specially crafted ZIP file.
NOTE: This only affects the Enterprise and Reporting Console editions.An unspecified error in the load file functionality can be exploited via a specially crafted SCAN file.
NOTE: This only affects the Standard and Express editions.
Successful exploitation of these vulnerabilities may allow execution of arbitrary code, but requires tricking a user into opening a malicious file.
Impact
- Remote Code Execution
System / Technologies affected
- IBM Raditional Appscan 5.x
- IBM Raditional Appscan 6.x
- IBM Raditional Appscan 7.x
- IBM Raditional Appscan 8.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to a fixed version.
http://www.ibm.com/support/docview.wss?uid=swg21515110
Vulnerability Identifier
Source
Related Link
Share with