CVE-2012-2684: SQL Injection
Multiple SQL injection vulnerabilities in the getsamplefiltersbysignature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2684?
CVE-2012-2684 is classified as a medium severity vulnerability due to the potential for arbitrary SQL command execution.
How do I fix CVE-2012-2684?
To fix CVE-2012-2684, upgrade to Cumin version 0.1.5444 or later.
What impact does CVE-2012-2684 have on my system?
CVE-2012-2684 allows remote attackers to execute arbitrary SQL commands, which can lead to data breaches or system compromise.
Which software versions are affected by CVE-2012-2684?
CVE-2012-2684 affects Cumin versions up to 0.1.5444, including several releases such as 0.1.5192-4 and earlier.
Are there any known exploits for CVE-2012-2684?
Yes, CVE-2012-2684 has the potential for exploitation by attackers, but specific exploits have not been publicly documented.