CVE-2017-15367: SQL Injection
Published Mar 7, 2018
·Updated
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.
Affected Software
3 affected componentsFixes available
composer/bacula-web/bacula-web<8.0.0-rc2
8.0.0-rc2
Bacula Bacula-Web<=7.4.0
Bacula Bacula-Web=8.0.0-rc1
Remediation
Event History
Mar 7, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 14, 2022
Advisory Published
02:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-15367?
CVE-2017-15367 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2017-15367?
To fix CVE-2017-15367, upgrade to Bacula-web version 8.0.0-rc2 or later.
3
What are the potential impacts of CVE-2017-15367?
CVE-2017-15367 can lead to unauthorized access to the Bacula database and privilege escalation depending on the server configuration.
4
Which versions are affected by CVE-2017-15367?
CVE-2017-15367 affects Bacula-web versions prior to 8.0.0-rc2 and includes versions up to 7.4.0.
5
What type of vulnerability is CVE-2017-15367?
CVE-2017-15367 is a SQL Injection vulnerability that allows attackers to manipulate database queries.