CVE-2014-2949: SQL Injection
Published Jun 18, 2014
·Updated
SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
F5 ARX Data Manager=3.0.0
F5 ARX Data Manager=3.1.0
Event History
Jun 18, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2949?
CVE-2014-2949 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2014-2949?
To fix CVE-2014-2949, upgrade F5 ARX Data Manager to a version that is not vulnerable, such as versions beyond 3.1.0.
3
Who can exploit CVE-2014-2949?
CVE-2014-2949 can be exploited by remote authenticated users with access to the web service.
4
What kind of attacks can be performed using CVE-2014-2949?
CVE-2014-2949 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
5
Which versions of F5 ARX Data Manager are affected by CVE-2014-2949?
CVE-2014-2949 affects F5 ARX Data Manager version 3.0.0 and 3.1.0.