First published: Tue Dec 16 2014(Updated: )
SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Release Automation | <=4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8248 is considered a high-severity SQL injection vulnerability that could allow remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2014-8248, upgrade to CA Release Automation version 4.7.1 b448 or later, which patches this SQL injection vulnerability.
CVE-2014-8248 affects CA Release Automation versions prior to 4.7.1 b448.
Remote authenticated users can exploit CVE-2014-8248 to execute arbitrary SQL commands due to insufficient input validation.
Exploitation of CVE-2014-8248 may lead to unauthorized access to the database and potential data manipulation or retrieval.