First published: Wed Dec 03 2014(Updated: )
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =21 | |
OpenVAS Manager | <=4.0.5 | |
OpenVAS Manager | =5.0.0 | |
OpenVAS Manager | =5.0.0-beta1 | |
OpenVAS Manager | =5.0.0-beta10 | |
OpenVAS Manager | =5.0.0-beta11 | |
OpenVAS Manager | =5.0.0-beta12 | |
OpenVAS Manager | =5.0.0-beta13 | |
OpenVAS Manager | =5.0.0-beta2 | |
OpenVAS Manager | =5.0.0-beta3 | |
OpenVAS Manager | =5.0.0-beta4 | |
OpenVAS Manager | =5.0.0-beta5 | |
OpenVAS Manager | =5.0.0-beta6 | |
OpenVAS Manager | =5.0.0-beta7 | |
OpenVAS Manager | =5.0.0-beta8 | |
OpenVAS Manager | =5.0.0-beta9 | |
OpenVAS Manager | =5.0.1 | |
OpenVAS Manager | =5.0.2 | |
OpenVAS Manager | =5.0.3 | |
OpenVAS Manager | =5.0.4 | |
OpenVAS Manager | =5.0.5 | |
OpenVAS Manager | =5.0.6 | |
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9220 has a severity rating that indicates it poses a medium risk to affected systems.
To fix CVE-2014-9220, upgrade OpenVAS Manager to version 4.0.6 or 5.0.7 or later.
CVE-2014-9220 allows remote attackers to execute arbitrary SQL commands, potentially compromising database integrity.
CVE-2014-9220 affects OpenVAS Manager versions prior to 4.0.6 and 5.x prior to 5.0.7.
CVE-2014-9220 can be exploited by remote attackers who have access to send OMP commands to the OpenVAS Manager.