PT-2018-11195 · Micro Focus · Micro Focus Secure Messaging Gateway
Mehmet Ince
·
Publicado
2018-06-29
·
Atualizado
2019-10-09
·
CVE-2018-12464
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Micro Focus Secure Messaging Gateway versions prior to 471
Description
A SQL injection issue in the web administration and quarantine components allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account.
Recommendations
For versions prior to 471, update to version 471 or later to resolve the issue. As a temporary workaround, consider restricting access to the web administration and quarantine components to minimize the risk of exploitation.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Micro Focus Secure Messaging Gateway