CVE-2017-8790: Critical severity accellion secure file transfer appliance vulnerability
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8790?
CVE-2017-8790 has a CVSS score of 7.5, indicating high severity due to its potential for LDAP injection.
2
How do I fix CVE-2017-8790?
To fix CVE-2017-8790, upgrade your Accellion FTA device to version FTA_9_12_180 or later.
3
What impact does CVE-2017-8790 have on my system?
CVE-2017-8790 can allow attackers to manipulate LDAP queries, potentially leading to unauthorized access to sensitive data.
4
Which versions are affected by CVE-2017-8790?
CVE-2017-8790 affects Accellion File Transfer Appliance versions prior to 9_12_180.
5
Is there a workaround for CVE-2017-8790 if I cannot update?
Currently, there are no known workarounds for CVE-2017-8790; upgrading is the recommended solution.