Vulnerability Description
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Openpages Grc Platform | 7.0.0.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21970590Vendor Advisory
- http://www.securityfocus.com/bid/79682
- http://www-01.ibm.com/support/docview.wss?uid=swg21970590Vendor Advisory
- http://www.securityfocus.com/bid/79682
FAQ
What is CVE-2015-5049?
CVE-2015-5049 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecifi...
How severe is CVE-2015-5049?
CVE-2015-5049 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5049?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Openpages Grc Platform.