PT-2014-3400 · F Secure+2 · F-Secure Anti-Virus For Windows Servers+7

Andrea Micalizzi

+1

·

Published

2014-04-18

·

Updated

2014-04-21

·

CVE-2013-7369

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions F-Secure Anti-Virus for Microsoft Exchange Server versions prior to HF02 F-Secure Anti-Virus for Windows Servers 9.00 versions prior to HF09 F-Secure Anti-Virus for Citrix Servers 9.00 versions prior to HF09 F-Secure Email and Server Security 9.20 versions prior to HF01 F-Secure Server Security 9.20 versions prior to HF01
Description The issue allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to the GetCommand function. This is a result of a SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control.
Recommendations For F-Secure Anti-Virus for Microsoft Exchange Server versions prior to HF02, update to a version that includes HF02 or later. For F-Secure Anti-Virus for Windows Servers 9.00 versions prior to HF09, update to a version that includes HF09 or later. For F-Secure Anti-Virus for Citrix Servers 9.00 versions prior to HF09, update to a version that includes HF09 or later. For F-Secure Email and Server Security 9.20 versions prior to HF01, update to a version that includes HF01 or later. For F-Secure Server Security 9.20 versions prior to HF01, update to a version that includes HF01 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7369

Affected Products

Citrix Servers
F-Secure Anti-Virus For Citrix Servers
F-Secure Anti-Virus For Microsoft Exchange
F-Secure Anti-Virus For Windows Servers
F-Secure Email/Server Security
F-Secure Server Security
Exchange Server
Windows Server