Arbitrary Command Execution in IBM Global Console Manager Products
CVE-2014-3085
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 17 August 2014
What is CVE-2014-3085?
IBM Global Console Manager switches, specifically the GCM16 and GCM32 models running firmware prior to version 1.20.20.23447, are susceptible to a security flaw that allows authenticated users to execute arbitrary commands. This vulnerability arises from improper handling of the lpres parameter in the systest.php script, which can be exploited through shell metacharacters. Attackers leveraging this weakness could gain unauthorized access and control over the affected systems, potentially leading to security breaches and data compromise.