A vulnerability has been reported in the J2EE/RI (Reference Implementation) Pointbase 4.6 database that could permit remote attackers to execute arbitrary commands on a system hosting the software. This issue may reportedly be exploited through a malicious SQL statement that will cause an executable on the host file system to be run. Denial of service attacks and exposure of sensitive information may also be the result of successful exploitation. This vulnerability is similar in nature to the issue described in BID 8773. The vulnerability was reported for J2EE/RI 1.4 on Windows platforms. Other versions and releases for different platforms are also likely affected.
A vulnerability has been reported in the J2EE/RI (Reference Implementation) Pointbase 4.6 database that could permit remote attackers to execute arbitrary commands on a system hosting the software. This issue may reportedly be exploited through a malicious SQL statement that will cause an executable on the host file system to be run. Denial of service attacks and exposure of sensitive information may also be the result of successful exploitation. This vulnerability is similar in nature to the issue described in BID 8773. The vulnerability was reported for J2EE/RI 1.4 on Windows platforms. Other versions and releases for different platforms are also likely affected.