An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web parameter can cause a command injection. An authenticated attacker can send a crafted web request to trigger this vulnerability.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0315 | Mitigation Third Party Advisory |
Configurations
Information
Published : 2018-09-07 10:29
Updated : 2022-12-14 06:20
NVD link : CVE-2016-9044
Mitre link : CVE-2016-9044
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
informationbuilders
- webfocus