First published: Fri May 05 2017(Updated: )
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion Secure File Transfer Appliance | <=9_12_40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8790 has a CVSS score of 7.5, indicating high severity due to its potential for LDAP injection.
To fix CVE-2017-8790, upgrade your Accellion FTA device to version FTA_9_12_180 or later.
CVE-2017-8790 can allow attackers to manipulate LDAP queries, potentially leading to unauthorized access to sensitive data.
CVE-2017-8790 affects Accellion File Transfer Appliance versions prior to 9_12_180.
Currently, there are no known workarounds for CVE-2017-8790; upgrading is the recommended solution.