CVE-2018-11065
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to read certain data. Embedded WorkPoint is upgraded to version 4.10.16, which contains a fix for the vulnerability.
El componente WorkPoint que está embebido en RSA Archer, en versiones 6.1.x, 6.2.x, 6.3.x anteriores a la 6.3.0.7 y 6.4.x anteriores a la 6.4.0.1, contiene una vulnerabilidad de inyección SQL. Un usuario malicioso podría explotar esta vulnerabilidad para ejecutar comandos SQL en la base de datos del backend para leer ciertos datos. El WorkPoint embebido se ha actualizado a la versión 4.10.16, que contiene una solución para la vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-08-21 CVE Published
- 2024-09-16 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Aug/31 | Mailing List | |
http://www.securityfocus.com/bid/105128 | Third Party Advisory | |
http://www.securitytracker.com/id/1041540 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.1.0.0 < 6.1.0.3 Search vendor "Rsa" for product "Archer" and version " >= 6.1.0.0 < 6.1.0.3" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.2.0.0 < 6.2.0.10 Search vendor "Rsa" for product "Archer" and version " >= 6.2.0.0 < 6.2.0.10" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.3.0.0 < 6.3.0.7 Search vendor "Rsa" for product "Archer" and version " >= 6.3.0.0 < 6.3.0.7" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.4.0.0 < 6.4.0.1 Search vendor "Rsa" for product "Archer" and version " >= 6.4.0.0 < 6.4.0.1" | - |
Affected
|