SQL injection in HP Network Automation - CVE-2017-5810

 

SQL injection in HP Network Automation - CVE-2017-5810

Published: May 10, 2017


Vulnerability identifier: #VU6505
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5810
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL commands in web application database.

The weakness exists due to insufficient sanitization of user-supplied input processed by the affected application. A remote unauthenticated attacker can send a specially crafted request that contains crafted parameter values and execute arbitrary SQL commands.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable website.

Affected software

HP Network Automation

How to mitigate CVE-2017-5810

Update to version 10.00.022, 10.11.03 or 10.21.01.


External References

Related Security Bulletins