CVE-2012-3000: SQL Injection
Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and 11.2.x before 11.2.1-HF3 allow remote authenticated users to execute arbitrary SQL commands via the defaultQuery parameter.
Affected Software
Event History
Frequently Asked Questions
What are the effects of CVE-2012-3000?
CVE-2012-3000 allows remote attackers to exploit multiple SQL injection vulnerabilities leading to unauthorized access to sensitive data.
How do I mitigate CVE-2012-3000?
To mitigate CVE-2012-3000, upgrade to F5 BIG-IP versions 11.2.0-HF3 or 11.2.1-HF3 or later.
Who is affected by CVE-2012-3000?
CVE-2012-3000 affects various versions of F5 BIG-IP products, including Local Traffic Manager, Global Traffic Manager, and Application Security Manager.
Is CVE-2012-3000 rated high severity?
Yes, CVE-2012-3000 has a high severity rating due to its potential impact on system integrity and confidentiality.
When was CVE-2012-3000 discovered?
CVE-2012-3000 was publicly disclosed in early 2013, highlighting significant vulnerabilities within F5 BIG-IP products.