Untrusted search path and argument injection vulnerability in the VersantD...
Vulnerability Description
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-1319
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=bugtraq&m=120468784112145&w=2
- https://www.exploit-db.com/exploits/5213
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40997
- http://secunia.com/advisories/29230
- http://www.securityfocus.com/bid/28097
- http://www.vupen.com/english/advisories/2008/0764/references
- http://aluigi.altervista.org/adv/versantcmd-adv.txt
- http://www.securityfocus.com/archive/1/489139/100/0/threaded
- http://securityreason.com/securityalert/3738
Affected Vendor
versant
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.