CVE-2019-18464
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the database.
En Progress MOVEit Transfer versiones 10.2 anteriores a 10.2.6 (2018.3), versiones 11.0 anteriores a 11.0.4 (2019.0.4) y versiones 11.1 anteriores a 11.1.3 (2019.1.3), se han encontrado múltiples vulnerabilidades de inyección SQL en la API REST que podrían permitir a un atacante no autenticado conseguir acceso no autorizado a la base de datos. Dependiendo del motor de base de datos que está siendo usado (MySQL, Microsoft SQL Server o Azure SQL), un atacante puede ser capaz de inferir información sobre la estructura y el contenido de la base de datos o puede ser capaz de alterar la base de datos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-10-25 CVE Reserved
- 2019-10-31 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.ipswitch.com/s/article/SQL-Injection-Vulnerability-2 | 2019-11-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ipswitch Search vendor "Ipswitch" | Moveit Transfer Search vendor "Ipswitch" for product "Moveit Transfer" | >= 10.2.0 < 10.2.6 Search vendor "Ipswitch" for product "Moveit Transfer" and version " >= 10.2.0 < 10.2.6" | - |
Affected
| ||||||
Ipswitch Search vendor "Ipswitch" | Moveit Transfer Search vendor "Ipswitch" for product "Moveit Transfer" | >= 11.0 < 11.0.4 Search vendor "Ipswitch" for product "Moveit Transfer" and version " >= 11.0 < 11.0.4" | - |
Affected
| ||||||
Ipswitch Search vendor "Ipswitch" | Moveit Transfer Search vendor "Ipswitch" for product "Moveit Transfer" | >= 11.1 < 11.1.3 Search vendor "Ipswitch" for product "Moveit Transfer" and version " >= 11.1 < 11.1.3" | - |
Affected
|