CVE-2019-12989: Citrix SD-WAN and NetScaler SQL Injection Vulnerability
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Other sources
Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12989?
The severity of CVE-2019-12989 is critical with a score of 9.8.
What is the affected software for CVE-2019-12989?
The affected software for CVE-2019-12989 is Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8.
What is SQL Injection vulnerability?
SQL Injection vulnerability is a code injection technique where an attacker can insert malicious SQL statements into an application's database query.
How can I fix CVE-2019-12989?
To fix CVE-2019-12989, upgrade your Citrix SD-WAN to version 10.2.3 or later, and upgrade your NetScaler SD-WAN to version 10.0.8 or later.
Where can I find more information about CVE-2019-12989?
You can find more information about CVE-2019-12989 in the following references: [http://packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html](http://packetstormsecurity.com/files/153638/Citrix-SD-WAN-Appliance-10.2.2-Authentication-Bypass-Remote-Command-Execution.html), [http://www.securityfocus.com/bid/109133](http://www.securityfocus.com/bid/109133), [https://support.citrix.com/article/CTX251987](https://support.citrix.com/article/CTX251987).