First published: Tue Jul 16 2019(Updated: )
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler SD-WAN | >=10.0.0<10.0.8 | |
Citrix SD-WAN | >=10.2.0<10.2.3 | |
Citrix SD-WAN and NetScaler | ||
>=10.0.0<10.0.8 | ||
>=10.2.0<10.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-12989 is critical with a score of 9.8.
The affected software for CVE-2019-12989 is Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8.
SQL Injection vulnerability is a code injection technique where an attacker can insert malicious SQL statements into an application's database query.
To fix CVE-2019-12989, upgrade your Citrix SD-WAN to version 10.2.3 or later, and upgrade your NetScaler SD-WAN to version 10.0.8 or later.
You can find more information about CVE-2019-12989 in the following references: [http://packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html](http://packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html), [http://www.securityfocus.com/bid/109133](http://www.securityfocus.com/bid/109133), [https://support.citrix.com/article/CTX251987](https://support.citrix.com/article/CTX251987).