First published: Fri Jan 08 2016(Updated: )
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.
Credit: cret@cert.org cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Software WhatsUp Gold | =16.3 | |
Progress Software WhatsUp Gold | =16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8261 is considered a critical vulnerability due to potential SQL injection attacks that could compromise the database.
To fix CVE-2015-8261, upgrade Ipswitch WhatsUp Gold to version 16.4 or later where this vulnerability has been addressed.
CVE-2015-8261 allows remote attackers to execute arbitrary SQL commands, leading to data exposure or manipulation.
CVE-2015-8261 affects Ipswitch WhatsUp Gold versions prior to 16.4, specifically version 16.3.
Attackers can exploit CVE-2015-8261 by sending crafted SOAP requests that include malicious serialized XML objects.