QID 731204
Date Published: 2024-02-28
QID 731204: Accellion File Transfer Appliance (FTA) Multiple Security Vulnerabilities (CVE-2021-27101,CVE-2021-27104)
Accellion File Transfer Appliance is a file transfer application that is used to share files.
CVE-2021-27101: FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html.
CVE-2021-27104: FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints.
Affected Versions:
Accellion FTA versions 9_12_370 and earlier
Patch Versions:
Accellion FTA_version 9_12_380 and later
QID Detection Logic (Unauthenticated):
This QID detects Accellion File Transfer Appliance from WebUI.
Successful exploitation of these vulnerabilities may allow an attacker to either manipulate with database server or execute arbitrary command on the target system.
Solution
Please contact vendor Accellion for patch details.
Vendor References
- CVE-2021-27101 -
github.com/accellion/CVEs/blob/main/CVE-2021-27101.txt - CVE-2021-27104 -
github.com/accellion/CVEs/blob/main/CVE-2021-27104.txt
CVEs related to QID 731204
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-27101 |
|
||
| CVE-2021-27104 |
|