← Back

CVE-2012-3000

nvd nist
Published: Jan 30, 2014Modified: Apr 29, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and 11.2.x before 11.2.1-HF3 allow remote authenticated users to execute arbitrary SQL commands via the defaultQuery parameter.

Affected (49)

10 products
Big Ip Webaccelerator
Big Ip Global Traffic Manager
Big Ip Local Traffic Manager
Big Ip Protocol Security Module
Big Ip Wan Optimization Manager
Big Ip Link Controller
Big Ip Analytics
Big Ip Access Policy Manager
Big Ip Edge Gateway
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.0.0 hf1
Version 11.1.0
Version 11.1.0 hf2
Version 11.2.0
Version 11.2.1
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.0.0 hf1
Version 11.1.0
Version 11.1.0 hf2
Version 11.2.0
Version 11.2.1
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Configuration E
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Configuration F
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Configuration G
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Configuration H
6 vulnerable
Configuration I
7 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.1.0
Version 11.2.0
Version 11.2.1
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1
Configuration J
4 vulnerable
Vulnerable SoftwareAffected Versions
F5
Version 11.0.0
Version 11.1.0
Version 11.2.0
Version 11.2.1

References (16)

Source: cret@cert.org
Source: cret@cert.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.