First published: Fri Dec 01 2017(Updated: )
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ark-web A-reserve | <=3.8.6 | |
Ark-web A-reserve | <=3.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-10899 is considered high due to the potential for arbitrary SQL command execution.
To fix CVE-2017-10899, upgrade to A-Reserve version 3.8.7 or later.
CVE-2017-10899 affects A-Reserve versions 3.8.6 and earlier.
CVE-2017-10899 is an SQL injection vulnerability.
Attackers can execute arbitrary SQL commands through unspecified vectors in affected versions.