Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU428
Risk: Low
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2015-6665
CWE-ID:
CWE-564 - SQL Injection: Hibernate
Exploit availability: No
DescriptionThe vulnerability allows user with elevated permissions to get access to sensitive information.
The weakness exists due to SQL injection. The attacker inject specially crafted code inunsufficiently filtered SQL comments.
Successful exploitation of this vulnerability allows a malicious user to obtain potentially sensitive information.
Update to 7.39.
https://www.drupal.org/drupal-7.39-release-notes
Drupal: 7.1 - 7.38
CPE2.3https://www.drupal.org/SA-CORE-2015-003
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.