peter bassill · operator
$ cve CVE-2012-2171 JSON

CVE-2012-2171 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 5.1% (pctl 92)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS5.14% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2012-06-22
Last modified2026-06-16

Affected (18)

VendorProduct
ibmds storage manager host software
ibmds4100
ibmds4200
ibmds4300
ibmds4400
ibmds4500
ibmds4700
ibmds4800
ibmsystem storage dcs3700 storage subsystem
ibmsystem storage ds3200
ibmsystem storage ds3300
ibmsystem storage ds3400
ibmsystem storage ds3512
ibmsystem storage ds3524
ibmsystem storage ds3950 express
ibmsystem storage ds5020 disk controller
ibmsystem storage ds5100 storage controller
ibmsystem storage ds5300 storage controller

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD