CVE-2018-15904: SQL Injection
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2018-15904.
What is the severity level of CVE-2018-15904?
The severity level of CVE-2018-15904 is critical with a score of 9.8.
Which software versions are affected by CVE-2018-15904?
The affected software versions are A10 ACOS Web Application Firewall (WAF) 2.7.1, 2.7.2, 4.1.0, 4.1.1, and 4.1.2.
What is the vulnerability description of CVE-2018-15904?
CVE-2018-15904 is a vulnerability in A10 ACOS Web Application Firewall (WAF) versions 2.7.1 and 2.7.2, 4.1.0, 4.1.1, and 4.1.2 that mishandles the configured rules for blocking SQL injection attacks.
How can I fix CVE-2018-15904?
To fix CVE-2018-15904, it is recommended to update the A10 ACOS Web Application Firewall (WAF) software to version 2.7.2-P12, 4.1.0-P11, 4.1.1-P8, or 4.1.2-P4.