Description
RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11885 | RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application. |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T03:32:36.574Z
Reserved: 2017-12-06T00:00:00.000Z
Link: CVE-2018-1252
No data.
Status : Modified
Published: 2018-06-05T12:29:00.243
Modified: 2024-11-21T03:59:28.190
Link: CVE-2018-1252
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD