F5 Networks ARX Data Manager CVE-2014-2949 SQL Injection Vulnerabilitiy
BID:68078
Info
F5 Networks ARX Data Manager CVE-2014-2949 SQL Injection Vulnerabilitiy
| Bugtraq ID: | 68078 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2949 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2014 12:00AM |
| Updated: | Aug 14 2014 12:13AM |
| Credit: | Andrea Micalizzi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
F5 Networks ARX Data Manager CVE-2014-2949 SQL Injection Vulnerabilitiy
F5 Networks ARX Data Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
F5 Networks ARX Data Manager 3.0.0 and 3.1.0 are vulnerable; other versions may also be affected.
F5 Networks ARX Data Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.
F5 Networks ARX Data Manager 3.0.0 and 3.1.0 are vulnerable; other versions may also be affected.
Exploit / POC
F5 Networks ARX Data Manager CVE-2014-2949 SQL Injection Vulnerabilitiy
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
F5 Networks ARX Data Manager CVE-2014-2949 SQL Injection Vulnerabilitiy
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
F5 Networks ARX Data Manager CVE-2014-2949 SQL Injection Vulnerabilitiy
References:
References: