CVE-2021-27101: Accellion FTA SQL Injection Vulnerability
Accellion FTA 912370 and earlier is affected by SQL injection via a crafted Host header in a request to documentroot.html. The fixed version is FTA912380 and later.
Other sources
Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to documentroot.html.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Accellion File Transfer Applianceto a version that resolves this vulnerability.Fixed in FTA_9_12_380
Event History
Frequently Asked Questions
What is CVE-2021-27101?
CVE-2021-27101 is a SQL injection vulnerability affecting Accellion FTA 9_12_370 and earlier versions.
How does CVE-2021-27101 impact Accellion FTA?
CVE-2021-27101 allows an attacker to perform SQL injection by crafting a Host header in a request to document_root.html in Accellion FTA.
What is the severity level of CVE-2021-27101?
CVE-2021-27101 has a severity level of 9.8 (Critical).
How can I fix CVE-2021-27101?
To fix CVE-2021-27101, upgrade to Accellion FTA version FTA_9_12_380 or later.
Where can I find more information about CVE-2021-27101?
You can find more information about CVE-2021-27101 at the following references: [Github - CVE-2021-27101](https://github.com/accellion/CVEs/blob/main/CVE-2021-27101.txt), [Accellion FTA Product Page](https://www.accellion.com/products/fta/).