CVE-2014-8248: SQL Injection
SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8248?
CVE-2014-8248 is considered a high-severity SQL injection vulnerability that could allow remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2014-8248?
To fix CVE-2014-8248, upgrade to CA Release Automation version 4.7.1 b448 or later, which patches this SQL injection vulnerability.
What systems are affected by CVE-2014-8248?
CVE-2014-8248 affects CA Release Automation versions prior to 4.7.1 b448.
Who can exploit CVE-2014-8248?
Remote authenticated users can exploit CVE-2014-8248 to execute arbitrary SQL commands due to insufficient input validation.
What are the consequences of CVE-2014-8248?
Exploitation of CVE-2014-8248 may lead to unauthorized access to the database and potential data manipulation or retrieval.