orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Net.commerce | Ibm | 2.0 (including) | 2.0 (including) |
Net.commerce | Ibm | 3.0 (including) | 3.0 (including) |
Net.commerce | Ibm | 3.1 (including) | 3.1 (including) |
Net.commerce | Ibm | 3.1.1 (including) | 3.1.1 (including) |
Net.commerce | Ibm | 3.1.2 (including) | 3.1.2 (including) |
Net.commerce | Ibm | 3.2 (including) | 3.2 (including) |
Net.commerce_hosting_server | Ibm | 3.1.1 (including) | 3.1.1 (including) |
Net.commerce_hosting_server | Ibm | 3.1.2 (including) | 3.1.2 (including) |
Net.commerce_hosting_server | Ibm | 3.2 (including) | 3.2 (including) |
Websphere_commerce_suite | Ibm | 3.1.2 (including) | 3.1.2 (including) |
Websphere_commerce_suite | Ibm | 3.2 (including) | 3.2 (including) |
Websphere_commerce_suite | Ibm | 4.1 (including) | 4.1 (including) |
Websphere_commerce_suite | Ibm | 4.1.1 (including) | 4.1.1 (including) |