CVE-2017-12567: SQL Injection
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12567?
CVE-2017-12567 has a medium severity level, which indicates a moderate security risk.
How do I fix CVE-2017-12567?
To remediate CVE-2017-12567, users should upgrade to the latest version of the affected software, as patches are provided in the newer releases.
What products are affected by CVE-2017-12567?
CVE-2017-12567 affects Quest KACE Asset Management Appliance versions 6.4.120822 through 7.2, Systems Management Appliance versions 6.4.120822 through 7.2.101, and K1000 As A Service versions 7.0 through 7.2.
Can CVE-2017-12567 lead to data breaches?
Yes, due to SQL injection vulnerabilities, CVE-2017-12567 could potentially allow attackers to access sensitive data, leading to data breaches.
Is CVE-2017-12567 actively exploited?
While there may not be extensive reports of active exploitation, security best practices suggest immediate remediation due to the inherent risks associated with SQL injection vulnerabilities.