CVE-2012-2576: SQL Injection
Published Dec 20, 2017
·Updated
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
Affected Software
3 affected components
SolarWinds Backup Profiler<5.1.2
SolarWinds Storage Manager<5.1.2
SolarWinds Storage Profiler<5.1.2
Event History
Dec 20, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2576?
CVE-2012-2576 has a high severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2012-2576?
To fix CVE-2012-2576, upgrade to version 5.1.2 or later of the affected SolarWinds products.
3
What products are affected by CVE-2012-2576?
CVE-2012-2576 affects SolarWinds Backup Profiler, Storage Manager, and Storage Profiler prior to version 5.1.2.
4
What type of vulnerability is CVE-2012-2576?
CVE-2012-2576 is classified as an SQL injection vulnerability.
5
Can CVE-2012-2576 lead to unauthorized data access?
Yes, CVE-2012-2576 can allow attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access.