CVE-2012-0401: SQL Injection
Published Mar 20, 2012
·Updated
Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
5 affected components
RSA EnVision=4.0-sp1
RSA EnVision=4.0-sp2
RSA EnVision=4.0-sp3
RSA EnVision=4.0-sp4
RSA EnVision=4.1
Event History
Mar 20, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0401?
CVE-2012-0401 is categorized as a critical vulnerability due to its potential for remote authenticated users to execute arbitrary SQL commands.
2
How do I fix CVE-2012-0401?
To fix CVE-2012-0401, upgrade to EMC RSA enVision version 4.1 or apply Patch 4 for earlier versions.
3
Who is affected by CVE-2012-0401?
The vulnerability affects authenticated users of EMC RSA enVision versions 4.0 and 4.1 prior to Patch 4.
4
What kind of attacks can be executed through CVE-2012-0401?
CVE-2012-0401 allows attackers to exploit SQL injection vulnerabilities to execute arbitrary SQL commands.
5
Is CVE-2012-0401 a common vulnerability?
While specific to EMC RSA enVision, SQL injection vulnerabilities are a common threat in many web applications.