← Back

CVE-2018-15904

nvd nist
Published: Aug 27, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.

Affected (37)

1 product
Acos Web Application Firewall
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
A10networks
Version 2.7.1
Version 2.7.2
Version 2.7.2 p10
Version 2.7.2 p11
Version 2.7.2 p1
Version 2.7.2 p2
Version 2.7.2 p3
Version 2.7.2 p4
Version 2.7.2 p5
Version 2.7.2 p6
Version 2.7.2 p7-sp3
Version 2.7.2 p7
Version 2.7.2 p8
Version 2.7.2 p9
Version 4.1.0
Version 4.1.0 p10
Version 4.1.0 p1
Version 4.1.0 p2
Version 4.1.0 p3
Version 4.1.0 p4
Version 4.1.0 p5
Version 4.1.0 p6
Version 4.1.0 p7
Version 4.1.0 p8
Version 4.1.0 p9
Version 4.1.1
Version 4.1.1 p1
Version 4.1.1 p2
Version 4.1.1 p3
Version 4.1.1 p4
Version 4.1.1 p5
Version 4.1.1 p6
Version 4.1.1 p7
Version 4.1.2
Version 4.1.2 p1
Version 4.1.2 p2
Version 4.1.2 p3

Timeline

No history available yet.