Skip to main content

Special Announcement

  • 25 Jun 2024

    Announcement for Change of Chinese Name

    Please note that the Chinese name of HKCERT is changed from 「香港電腦保安事故協調中心」 to 「香港網絡安全事故協調中心」 with immediate effect.

    The English name, abbreviation, web address and email address remained unchanged.

IBM Installation Manager "iim:" URI Remote Library Injection Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 2 Oct 2009 4722 Views

RISK: Medium Risk

A vulnerability has been identified in IBM Installation Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error in the "IBMIM.exe" file when processing parameters passed to the "-vm" argument via the "iim:" URI, which could allow attackers to load a malicious librairy from a remote location (e.g. network share) by tricking a user into visiting a specially crafted web page, leading to arbitrary code execution.


Impact

  • Remote Code Execution

System / Technologies affected

  • IBM Installation Manager version 1.3.2 and prior


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Upgrade to IBM Installation Manager version 1.3.3 :
http://www-01.ibm.com/support/docview.wss?rs=0&uid=swg21407330


Vulnerability Identifier

  • No CVE information is available

Source


Related Link