First published: Wed Jun 18 2014(Updated: )
SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 ARX Data Manager | =3.0.0 | |
F5 ARX Data Manager | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2949 is classified as a high-severity SQL injection vulnerability.
To fix CVE-2014-2949, upgrade F5 ARX Data Manager to a version that is not vulnerable, such as versions beyond 3.1.0.
CVE-2014-2949 can be exploited by remote authenticated users with access to the web service.
CVE-2014-2949 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
CVE-2014-2949 affects F5 ARX Data Manager version 3.0.0 and 3.1.0.