CVE-2012-2007: SQL Injection
Published May 9, 2012
·Updated
SQL injection vulnerability in HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
4 affected components
HP Performance Insight=5.3
HP Performance Insight=5.41
HP Performance Insight=5.41.001
HP Performance Insight=5.41.002
Event History
May 9, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2007?
CVE-2012-2007 is considered a high severity vulnerability due to its SQL injection capability.
2
How do I fix CVE-2012-2007?
To fix CVE-2012-2007, upgrade to a patched version of HP Performance Insight that addresses this vulnerability.
3
What types of attacks are possible with CVE-2012-2007?
CVE-2012-2007 allows remote attackers to execute arbitrary SQL commands on the affected systems.
4
Which versions of HP Performance Insight are affected by CVE-2012-2007?
CVE-2012-2007 affects HP Performance Insight versions 5.3, 5.41, 5.41.001, and 5.41.002.
5
Can CVE-2012-2007 lead to data leakage?
Yes, exploiting CVE-2012-2007 can potentially lead to unauthorized access and data leakage from the database.