CVE-2017-15546: SQL Injection
Published Jan 25, 2018
·Updated
The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database.
Affected Software
8 affected components
EMC RSA Authentication Manager<=8.2
EMC RSA Authentication Manager=8.2-sp1
EMC RSA Authentication Manager=8.2-sp1_p1
EMC RSA Authentication Manager=8.2-sp1_p2
EMC RSA Authentication Manager=8.2-sp1_p3
EMC RSA Authentication Manager=8.2-sp1_p4
EMC RSA Authentication Manager=8.2-sp1_p5
EMC RSA Authentication Manager=8.2-sp1_p6
Event History
Jan 25, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-15546?
CVE-2017-15546 is a blind SQL injection vulnerability in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier.
2
How does CVE-2017-15546 affect EMC RSA Authentication Manager?
CVE-2017-15546 allows authenticated malicious users to read unencrypted data from the database in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier.
3
What is the severity of CVE-2017-15546?
CVE-2017-15546 has a severity rating of 4.3 (medium).
4
How can authenticated malicious users exploit CVE-2017-15546?
Authenticated malicious users can exploit CVE-2017-15546 by performing blind SQL injection attacks.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2017-15546?
The CWE ID associated with CVE-2017-15546 is CWE-89 (SQL Injection).