First published: Mon Aug 07 2017(Updated: )
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE Asset Management Appliance | =6.4.120822 | |
Quest KACE Asset Management Appliance | =7.0 | |
Quest KACE Asset Management Appliance | =7.0.121306 | |
Quest KACE Asset Management Appliance | =7.1 | |
Quest KACE Asset Management Appliance | =7.1.149 | |
Quest KACE Asset Management Appliance | =7.2 | |
Quest Kace Systems Management | =6.4.120822 | |
Quest Kace Systems Management | =7.0 | |
Quest Kace Systems Management | =7.0.121306 | |
Quest Kace Systems Management | =7.1 | |
Quest Kace Systems Management | =7.1.149 | |
Quest Kace Systems Management | =7.2 | |
Quest Kace Systems Management | =7.2.101 | |
Quest K1000 as a Service | =7.0 | |
Quest K1000 as a Service | =7.0.121306 | |
Quest K1000 as a Service | =7.1 | |
Quest K1000 as a Service | =7.1.149 | |
Quest K1000 as a Service | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12567 has a medium severity level, which indicates a moderate security risk.
To remediate CVE-2017-12567, users should upgrade to the latest version of the affected software, as patches are provided in the newer releases.
CVE-2017-12567 affects Quest KACE Asset Management Appliance versions 6.4.120822 through 7.2, Systems Management Appliance versions 6.4.120822 through 7.2.101, and K1000 As A Service versions 7.0 through 7.2.
Yes, due to SQL injection vulnerabilities, CVE-2017-12567 could potentially allow attackers to access sensitive data, leading to data breaches.
While there may not be extensive reports of active exploitation, security best practices suggest immediate remediation due to the inherent risks associated with SQL injection vulnerabilities.