CVE-2021-35484: SQL Injection
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35484?
CVE-2021-35484 is categorized as a high severity vulnerability due to its potential for exploitation via SQL injection.
How do I fix CVE-2021-35484?
To mitigate CVE-2021-35484, update Nokia IMPACT to a version newer than 19.11.2.10-20210118042150283.
What specifically is vulnerable in CVE-2021-35484?
CVE-2021-35484 affects the endpoint /ui/rest-proxy/campaign/statistic, allowing for SQL injection through the sortColumn parameter.
Who is affected by CVE-2021-35484?
Any authenticated user in Nokia IMPACT versions up to and including 19.11.2.10-20210118042150283 is at risk due to CVE-2021-35484.
What kind of attack is possible with CVE-2021-35484?
CVE-2021-35484 allows for a Time-based Boolean Blind SQL Injection attack, which can be used to access sensitive information.