Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities

BID:100563

CVE-2017-12731 | CVE-2017-12733 |

Info

Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities

Bugtraq ID: 100563
Class: Input Validation Error
CVE: CVE-2017-12733
CVE-2017-12731
Remote: Yes
Local: No
Published: Aug 30 2017 12:00AM
Updated: Aug 30 2017 12:00AM
Credit: OPW
Vulnerable: OPW SiteSentinel iSite ATG Console 195
OPW SiteSentinel iSite ATG Console 191
OPW SiteSentinel iSite ATG Console 189
OPW SiteSentinel iSite ATG Console 175
OPW SiteSentinel iSite ATG Console 170
OPW SiteSentinel iSite ATG Console 16Q3.1
OPW SiteSentinel Integra 500 Console 195
OPW SiteSentinel Integra 500 Console 191
OPW SiteSentinel Integra 500 Console 189
OPW SiteSentinel Integra 500 Console 175
OPW SiteSentinel Integra 500 Console 170
OPW SiteSentinel Integra 500 Console 16Q3.1
OPW SiteSentinel Integra 100 Console 195
OPW SiteSentinel Integra 100 Console 191
OPW SiteSentinel Integra 100 Console 189
OPW SiteSentinel Integra 100 Console 175
OPW SiteSentinel Integra 100 Console 170
OPW SiteSentinel Integra 100 Console 16Q3.1
Not Vulnerable: OPW SiteSentinel iSite ATG Console 17Q2.1
OPW SiteSentinel Integra 500 Console 17Q2.1
OPW SiteSentinel Integra 100 Console 17Q2.1

Discussion

Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities

Multiple OPW Products are prone to an SQL-injection vulnerability and an authentication-bypass vulnerability.

An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, modify the logic of SQL queries, compromise the software, retrieve information, or modify data; other consequences are possible as well.

The following products and versions are vulnerable:

SiteSentinel Integra 100 Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
SiteSentinel Integra 500 Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
SiteSentinel iSite ATG Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1

Solution / Fix

Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities

Solution:
Updates are available. Please see the references or vendor advisory for more information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report