Font Size Change

HOMEIT SecurityMeasures for Information Security VulnerabilitiesIPA/ISEC:Vulnerabilities:Security Alert for Vulnerability in Movable Type

PRINT PAGE

IT Security

IPA/ISEC:Vulnerabilities:Security Alert for Vulnerability in Movable Type

Published: Dec 8, 2010
>> JAPANESE

Information-technology Promotion Agency, Japan (IPA, Chairman Kazumasa Fujie) has issued a security alert concerning security vulnerability in Movable Type on December 8, 2010.
This vulnerability could allow an attacker to manipulate the database, enabling the disclosure and/or deletion of the information held in the Movable Type system.
To fix this vulnerability, update the software to the fixed version provided by the product vendor.

1.Overview

Movable Type is developed by Six Apart, Ltd.which is a web content management system software to create and manage the content of websites and blogs. Movable Type is vulnerable to SQL injection due to a flaw in its database processing. If exploited, an attacker could disclose and/or delete the information held in the Movable Type system by manipulating the database.

To get a fixed version, go to the following URL:
http://www.sixapart.jp/movabletype/news/2010/12/08-1100.html (Japanese)

For the latest information, refer to the following URL:
http://jvndb.jvn.jp/jvndb/JVNDB-2010-000061

IPA received a report concerning this vulnerability and countermeasure directly from the product vendor on December 2, 2010, and released it today after JPCERT Coordination Center (JPCERT/CC) made adjustments with the vendor.

2.Impact

An attacker could manipulate the database, enabling the disclosure and/or deletion of the information held in the Movable Type system when the website is attacked by SQL injection.

Security Alert for Vulnerability in Ichitaro Series

3.Solution

To fix this vulnerability, update the software to the fixed version provided by the product vendor.

4.CVSS Severity

(1)Evaluation Result

Severity Rating
(CVSS base score)
□ Low
(0.0~3.9)
■ Medium
(4.0~6.9)
□ High
(7.0~10.0)
CVSS base score  
6.8

(2) Base Score Metrics

AV:Access Vector □ Local □ Adjacent
 Network
■ Network
AC:Access Complexity □ High ■ Medium □ Low
Au:Authentication □ Multiple □ Single ■ None
C:Confidentiality Impact □ None ■ Partial □ Complete
I:Integrity Impact □ None ■ Partial □ Complete
A:Availability Impact □ None ■ Partial □ Complete

■:Selected Values

5.CWE Type

This vulnerability has been CWE classified as "SQL Injection (CWE-89)".

Contact

IT Security Center,
Information-technology Promotion Agency, Japan (ISEC/IPA)
E-mail: