CVE-2021-40842
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visited by anyone with network access to the server could be used to blindly execute arbitrary SQL statements on the backend database. Version 7.12.0 and all versions prior to 7.11.2 are affected.
Proofpoint Insider Threat Management Server contiene una vulnerabilidad de inyección SQL en la consola web. La vulnerabilidad se presenta debido a que no se comprueba la entrada del parámetro del nombre de la base de datos que se requiere en determinadas API no autenticadas. Una URL maliciosa visitada por cualquier persona con acceso a la red del servidor podría ser usada para ejecutar ciegamente sentencias SQL arbitrarias en la base de datos del backend. La versión 7.12.0 y todas las versiones anteriores a 7.11.2 están afectadas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-10 CVE Reserved
- 2021-10-13 CVE Published
- 2024-06-28 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.proofpoint.com/us/security/security-advisories | 2021-10-19 | |
https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2021-0008 | 2021-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Proofpoint Search vendor "Proofpoint" | Insider Threat Management Server Search vendor "Proofpoint" for product "Insider Threat Management Server" | < 7.11.2 Search vendor "Proofpoint" for product "Insider Threat Management Server" and version " < 7.11.2" | - |
Affected
| ||||||
Proofpoint Search vendor "Proofpoint" | Insider Threat Management Server Search vendor "Proofpoint" for product "Insider Threat Management Server" | 7.12.0 Search vendor "Proofpoint" for product "Insider Threat Management Server" and version "7.12.0" | - |
Affected
|