SB2016101207 - SQL injection in Network Level Service



SB2016101207 - SQL injection in Network Level Service

Published: October 12, 2016 Updated: October 13, 2016

Security Bulletin ID SB2016101207
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) SQL injection (CVE-ID: CVE-2016-6443)

The vulnerability allow a remote authenticated user to perform SQL injection attack and affect target system confidentiality.
The weakness is caused by insufficient validation of user-supplied input within SQL queries. By sending a specially crafted URLs containing malicious SQL statements, attackers can define database values.
Successful exploitation of the vulnerability will result in compromise of confidentiality. Repeated exploitation may cause denial of service on the vulnerable system.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.