CVE-2012-2171

medium
Published 2012-06-22 · Modified 2026-04-29
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager before 10.83.xx.18 on DS Series devices allows remote authenticated users to execute arbitrary SQL commands via the selectedModuleOnly parameter in a state_viewmodulelog action to the ModuleServlet URI.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/connections/blogs/PSIRT/entry/secbulletin_stg-storage_cve-2012-2171_cve-2012-2172

Application impact

VendorProductVersionsFixed
ibm ibmds_storage_manager_host_software{"endIncluding":"10.83"}
ibm ibmds_storage_manager_host_software10.8
ibm ibmds_storage_manager_host_software10.60.x5.14

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.