Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dr. Benjamin Hess

Researcher fromSySS GmbH
#19948of 53,779
13Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-18007
6.5
2021-04-01
Emps · Emps · CVE-2021-28969
Name of the Vulnerable Software and Affected Versions: eMPS versions prior to 9.0.3 Description: The issue allows remote authenticated users to conduct SQL injection attacks via the `sort by` parameter to the email search feature. Recommendations: For versions prior to 9.0.3, update to version 9.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the email search feature until the update is applied. Avoid using the `sort by` parameter in the affected feature until the issue is resolved.
PT-2021-18008
6.5
2021-04-01
Fireeye · Fireeye Ex 3500 Emps · CVE-2021-28970
Name of the Vulnerable Software and Affected Versions: FireEye EX 3500 eMPS versions 9.0.1.923211 through 9.0.2 Description: The issue allows remote authenticated users to conduct SQL injection attacks via the `job id` parameter to the "email search feature". According to the vendor, the issue is fixed in version 9.0.3. Recommendations: For versions 9.0.1.923211 through 9.0.2, update to version 9.0.3 to resolve the issue. As a temporary workaround, consider restricting access to the email search feature until the update is applied. Avoid using the `job id` parameter in the affected feature until the issue is resolved.