PT-2014-3400 · F Secure+2 · F-Secure Anti-Virus For Windows Servers+7
Andrea Micalizzi
+1
·
Published
2014-04-18
·
Updated
2014-04-21
·
CVE-2013-7369
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
F-Secure Anti-Virus for Microsoft Exchange Server versions prior to HF02
F-Secure Anti-Virus for Windows Servers 9.00 versions prior to HF09
F-Secure Anti-Virus for Citrix Servers 9.00 versions prior to HF09
F-Secure Email and Server Security 9.20 versions prior to HF01
F-Secure Server Security 9.20 versions prior to HF01
Description
The issue allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to the
GetCommand function. This is a result of a SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control.Recommendations
For F-Secure Anti-Virus for Microsoft Exchange Server versions prior to HF02, update to a version that includes HF02 or later.
For F-Secure Anti-Virus for Windows Servers 9.00 versions prior to HF09, update to a version that includes HF09 or later.
For F-Secure Anti-Virus for Citrix Servers 9.00 versions prior to HF09, update to a version that includes HF09 or later.
For F-Secure Email and Server Security 9.20 versions prior to HF01, update to a version that includes HF01 or later.
For F-Secure Server Security 9.20 versions prior to HF01, update to a version that includes HF01 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Citrix Servers
F-Secure Anti-Virus For Citrix Servers
F-Secure Anti-Virus For Microsoft Exchange
F-Secure Anti-Virus For Windows Servers
F-Secure Email/Server Security
F-Secure Server Security
Exchange Server
Windows Server