IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.Referenceshttp://www.ibm.com/support/docview.wss?uid=swg21992072http://www.securityfocus.com/bid/95447