PT-2019-6315 · Citrix · Netscaler Sd-Wan+1

Published

2019-07-15

·

Updated

2025-11-06

·

CVE-2019-12989

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Citrix SD-WAN versions 10.2.x through 10.2.2 NetScaler SD-WAN versions 10.0.x through 10.0.7
Description The issue is related to a lack of protection against SQL query structure, allowing for SQL injection. This could enable a remote attacker to execute arbitrary SQL queries.
Recommendations For Citrix SD-WAN versions 10.2.x through 10.2.2, update to version 10.2.3 or later. For NetScaler SD-WAN versions 10.0.x through 10.0.7, update to version 10.0.8 or later.

Exploit

Fix

OS Command Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00812
BDU:2023-00912
CVE-2019-12989

Affected Products

Citrix Sd-Wan
Netscaler Sd-Wan