PT-2015-6377 · Actian · Actian Matrix

Publicado

2015-06-13

·

Atualizado

2016-12-06

·

CVE-2015-3993

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Actian Matrix versions 5.1.x through 5.1.2.4 Actian Matrix versions 5.2.x through 5.2.0.1
Description The issue allows remote authenticated users to bypass intended write-access restrictions. This is achieved by referencing a table to execute an UPDATE statement.
Recommendations For Actian Matrix versions 5.1.x through 5.1.2.4, update to a version that includes the necessary security fixes to restrict unauthorized access to tables. For Actian Matrix versions 5.2.x through 5.2.0.1, apply configuration changes to enforce strict access controls and prevent unauthorized execution of UPDATE statements.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3993

Produtos afetados

Actian Matrix