First published: Mon Aug 27 2018(Updated: )
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
A10networks Acos Web Application Firewall | =2.7.1 | |
A10networks Acos Web Application Firewall | =2.7.2 | |
A10networks Acos Web Application Firewall | =2.7.2-p1 | |
A10networks Acos Web Application Firewall | =2.7.2-p10 | |
A10networks Acos Web Application Firewall | =2.7.2-p11 | |
A10networks Acos Web Application Firewall | =2.7.2-p2 | |
A10networks Acos Web Application Firewall | =2.7.2-p3 | |
A10networks Acos Web Application Firewall | =2.7.2-p4 | |
A10networks Acos Web Application Firewall | =2.7.2-p5 | |
A10networks Acos Web Application Firewall | =2.7.2-p6 | |
A10networks Acos Web Application Firewall | =2.7.2-p7 | |
A10networks Acos Web Application Firewall | =2.7.2-p7-sp3 | |
A10networks Acos Web Application Firewall | =2.7.2-p8 | |
A10networks Acos Web Application Firewall | =2.7.2-p9 | |
A10networks Acos Web Application Firewall | =4.1.0 | |
A10networks Acos Web Application Firewall | =4.1.0-p1 | |
A10networks Acos Web Application Firewall | =4.1.0-p10 | |
A10networks Acos Web Application Firewall | =4.1.0-p2 | |
A10networks Acos Web Application Firewall | =4.1.0-p3 | |
A10networks Acos Web Application Firewall | =4.1.0-p4 | |
A10networks Acos Web Application Firewall | =4.1.0-p5 | |
A10networks Acos Web Application Firewall | =4.1.0-p6 | |
A10networks Acos Web Application Firewall | =4.1.0-p7 | |
A10networks Acos Web Application Firewall | =4.1.0-p8 | |
A10networks Acos Web Application Firewall | =4.1.0-p9 | |
A10networks Acos Web Application Firewall | =4.1.1 | |
A10networks Acos Web Application Firewall | =4.1.1-p1 | |
A10networks Acos Web Application Firewall | =4.1.1-p2 | |
A10networks Acos Web Application Firewall | =4.1.1-p3 | |
A10networks Acos Web Application Firewall | =4.1.1-p4 | |
A10networks Acos Web Application Firewall | =4.1.1-p5 | |
A10networks Acos Web Application Firewall | =4.1.1-p6 | |
A10networks Acos Web Application Firewall | =4.1.1-p7 | |
A10networks Acos Web Application Firewall | =4.1.2 | |
A10networks Acos Web Application Firewall | =4.1.2-p1 | |
A10networks Acos Web Application Firewall | =4.1.2-p2 | |
A10networks Acos Web Application Firewall | =4.1.2-p3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2018-15904.
The severity level of CVE-2018-15904 is critical with a score of 9.8.
The affected software versions are A10 ACOS Web Application Firewall (WAF) 2.7.1, 2.7.2, 4.1.0, 4.1.1, and 4.1.2.
CVE-2018-15904 is a vulnerability in A10 ACOS Web Application Firewall (WAF) versions 2.7.1 and 2.7.2, 4.1.0, 4.1.1, and 4.1.2 that mishandles the configured rules for blocking SQL injection attacks.
To fix CVE-2018-15904, it is recommended to update the A10 ACOS Web Application Firewall (WAF) software to version 2.7.2-P12, 4.1.0-P11, 4.1.1-P8, or 4.1.2-P4.