PT-2018-11195 · Micro Focus · Micro Focus Secure Messaging Gateway
Mehmet Ince
·
Published
2018-06-29
·
Updated
2019-10-09
·
CVE-2018-12464
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Micro Focus Secure Messaging Gateway versions prior to 471
Description
A SQL injection issue in the web administration and quarantine components allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account.
Recommendations
For versions prior to 471, update to version 471 or later to resolve the issue. As a temporary workaround, consider restricting access to the web administration and quarantine components to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micro Focus Secure Messaging Gateway