PT-2018-15027 · Imperva · Imperva Securesphere

Published

2018-11-28

·

Updated

2019-02-04

·

CVE-2018-19646

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Imperva SecureSphere versions 13.0.10 through 13.2.10
Description The issue in Imperva SecureSphere allows remote attackers to execute arbitrary OS commands due to the mishandling of command-line arguments in the Python CGI scripts.
Recommendations For versions 13.0.10 through 13.2.10, update to a version that includes a fix for the mishandling of command-line arguments in Python CGI scripts.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19646

Affected Products

Imperva Securesphere