Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
BID:100563
CVE-2017-12731 | CVE-2017-12733 |Info
Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
| Bugtraq ID: | 100563 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12733 CVE-2017-12731 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2017 12:00AM |
| Updated: | Aug 30 2017 12:00AM |
| Credit: | OPW |
| Vulnerable: |
OPW SiteSentinel iSite ATG Console 195 OPW SiteSentinel iSite ATG Console 191 OPW SiteSentinel iSite ATG Console 189 OPW SiteSentinel iSite ATG Console 175 OPW SiteSentinel iSite ATG Console 170 OPW SiteSentinel iSite ATG Console 16Q3.1 OPW SiteSentinel Integra 500 Console 195 OPW SiteSentinel Integra 500 Console 191 OPW SiteSentinel Integra 500 Console 189 OPW SiteSentinel Integra 500 Console 175 OPW SiteSentinel Integra 500 Console 170 OPW SiteSentinel Integra 500 Console 16Q3.1 OPW SiteSentinel Integra 100 Console 195 OPW SiteSentinel Integra 100 Console 191 OPW SiteSentinel Integra 100 Console 189 OPW SiteSentinel Integra 100 Console 175 OPW SiteSentinel Integra 100 Console 170 OPW SiteSentinel Integra 100 Console 16Q3.1 |
| Not Vulnerable: |
OPW SiteSentinel iSite ATG Console 17Q2.1 OPW SiteSentinel Integra 500 Console 17Q2.1 OPW SiteSentinel Integra 100 Console 17Q2.1 |
Discussion
Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
Multiple OPW Products are prone to an SQL-injection vulnerability and an authentication-bypass vulnerability.
An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, modify the logic of SQL queries, compromise the software, retrieve information, or modify data; other consequences are possible as well.
The following products and versions are vulnerable:
SiteSentinel Integra 100 Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
SiteSentinel Integra 500 Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
SiteSentinel iSite ATG Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
Multiple OPW Products are prone to an SQL-injection vulnerability and an authentication-bypass vulnerability.
An attacker can exploit these issues to bypass certain security restrictions, perform unauthorized actions, modify the logic of SQL queries, compromise the software, retrieve information, or modify data; other consequences are possible as well.
The following products and versions are vulnerable:
SiteSentinel Integra 100 Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
SiteSentinel Integra 500 Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
SiteSentinel iSite ATG Console prior to 175, 175 through 189, 191 through 195 and 16Q3.1
Solution / Fix
Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple OPW Products ICSA-17-243-04 SQL Injection and Authentication Bypass Vulnerabilities
References:
References: