9.3
CVSSv2

CVE-2009-3518

Published: 01/10/2009 Updated: 02/10/2009
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and previous versions, as used in IBM Rational Robot and Rational Team Concert, allows remote malicious users to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm installation manager 1.3.0

ibm installation manager 1.2.1

ibm installation manager 1.3.1

ibm installation manager 1.0

ibm installation manager

Exploits

<!-- IBM Installation Manager <= 130 iim:// uri handler remote code execution exploit - IE by nine:situations:group::bruiser site: retrogodaltervistaorg/ vulnerable: IBM Rational Robot IBM Rational Team Concert possibly all Rational products, not Rational Appscan I see download location: www14softwareibmcom/webapp/downl ...