SQL Injection Vulnerabilities in IBM Lotus Connections
CVE-2008-4806

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
31 October 2008

What is CVE-2008-4806?

Multiple SQL injection vulnerabilities exist in IBM Lotus Connections 2.x prior to version 2.0.1, which can be exploited by remote attackers. By manipulating the 'sortField' parameter, attackers are able to execute arbitrary SQL commands, posing significant risks to data integrity and confidentiality. It is essential for users of affected versions to apply necessary updates to mitigate these security concerns.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.