| Weakness Name | Source | |
|---|---|---|
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data. |
| Metrics | Score | Severity | CVSS Vector | Source |
|---|---|---|---|---|
| V2 | 6.5 | AV:N/AC:L/Au:S/C:P/I:P/A:P | nvd@nist.gov |
Publication date : 2012-06-20 22h00 +00:00
Author : LiquidWorm
EDB Verified : No
Ibm>>Ds_storage_manager_host_software >> Version To (including) 10.83
Ibm>>Ds_storage_manager_host_software >> Version 10.8
Ibm>>Ds_storage_manager_host_software >> Version 10.60.x5.14
Ibm>>Ds4100 >> Version *
Ibm>>Ds4100 >> Version 1724
Ibm>>Ds4200 >> Version 1814
Ibm>>Ds4300 >> Version 1722
Ibm>>Ds4400 >> Version 1742
Ibm>>Ds4500 >> Version 1742
Ibm>>Ds4700 >> Version 1814
Ibm>>Ds4800 >> Version 1815
Ibm>>System_storage_dcs3700_storage_subsystem >> Version 1818
Ibm>>System_storage_ds3200 >> Version 1726
Ibm>>System_storage_ds3300 >> Version 1726
Ibm>>System_storage_ds3400 >> Version 1726
Ibm>>System_storage_ds3512 >> Version 1746
Ibm>>System_storage_ds3524 >> Version 1746
Ibm>>System_storage_ds3950_express >> Version 1814
Ibm>>System_storage_ds5020_disk_controller >> Version 1814-20a
Ibm>>System_storage_ds5100_storage_controller >> Version 1818
Ibm>>System_storage_ds5300_storage_controller >> Version 1818