HIGH · 7.5

CVE-2012-3000

Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR We...

Vulnerability Description

Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and 11.2.x before 11.2.1-HF3 allow remote authenticated users to execute arbitrary SQL commands via the defaultQuery parameter.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
F5Big-Ip Webaccelerator11.0.0
F5Big-Ip Global Traffic Manager11.0.0
F5Big-Ip Local Traffic Manager11.0.0
F5Big-Ip Protocol Security Module11.0.0
F5Big-Ip Wan Optimization Manager11.0.0
F5Big-Ip Link Controller11.0.0
F5Big-Ip Analytics11.0.0
F5Big-Ip Application Security Manager11.0.0
F5Big-Ip Access Policy Manager11.1.0
F5Big-Ip Edge Gateway11.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3000?

CVE-2012-3000 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR We...

How severe is CVE-2012-3000?

CVE-2012-3000 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3000?

Check the references section above for vendor advisories and patch information. Affected products include: F5 Big-Ip Webaccelerator, F5 Big-Ip Global Traffic Manager, F5 Big-Ip Local Traffic Manager, F5 Big-Ip Protocol Security Module, F5 Big-Ip Wan Optimization Manager.