CVE-2017-6195: SQL Injection
Published May 18, 2017
·Updated
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
Affected Software
4 affected components
Ipswitch MOVEit DMZ<=8.1
Ipswitch MOVEit DMZ=8.2
Ipswitch MOVEit DMZ=8.3
Ipswitch MOVEit Transfer 2017=9.0
Remediation
Event History
May 18, 2017
CVE Published
via MITRE·06:13 AM
Data Sourced
via MITRE·06:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-6195?
CVE-2017-6195 is classified as a critical vulnerability due to its ability to allow pre-authentication blind SQL injection.
2
How do I fix CVE-2017-6195?
To fix CVE-2017-6195, upgrade to MOVEit Transfer version 9.0.0.201 or MOVEit DMZ versions 8.3.0.30 or 8.2.0.20.
3
Which versions of MOVEit are affected by CVE-2017-6195?
CVE-2017-6195 affects Ipswitch MOVEit Transfer 2017 prior to 9.0.0.201 and MOVEit DMZ versions prior to 8.3.0.30.
4
Is CVE-2017-6195 exploitable remotely?
Yes, CVE-2017-6195 is exploitable remotely since it allows blind SQL injection without authentication.
5
What type of vulnerability is CVE-2017-6195?
CVE-2017-6195 is a blind SQL injection vulnerability that can be exploited pre-authentication.