CVE-2012-3000

CWE-89SQL Injection3 documents3 sources
Severity
7.5HIGH
EPSS
1.3%
top 20.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 17

Description

Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and 11.2.x before 11.2.1-HF3 allow remote authenticated users to execute arbitrary SQL commands via the defaultQuery parameter.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages10 packages

NVDf5/big-ip_edge_gateway4 versions+3
NVDf5/big-ip_link_controller4 versions+3
NVDf5/big-ip_analytics4 versions+3
NVDf5/big-ip_webaccelerator4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-qwc3-2jvx-f4c4: Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings2022-05-17
CVEList
CVE-2012-3000: Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings2014-01-30