CVE-2013-4058

EUVD-2013-3989
Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
ibminfosphere_information_server
8.5
ibminfosphere_information_server
8.5.0.1
ibminfosphere_information_server
8.5.0.2
ibminfosphere_information_server
8.5.0.3
ibminfosphere_information_server
8.7
ibminfosphere_information_server
8.7.0.1
ibminfosphere_information_server
8.7.0.2
ibminfosphere_information_server
9.1
ibminfosphere_information_server
9.1.0.1
ibminfosphere_information_server
9.1.2
𝑥
= Vulnerable software versions