peter bassill · operator
$ cve CVE-2018-12464 JSON

CVE-2018-12464 EXPLOIT

10.0
CRITICAL · CVSS 3.0 · EPSS 80.7% (pctl 100)

Patch early

A public exploit exists.

Description

A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).

Scoring

CVSS10.0 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS80.67% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2018-06-29
Last modified2026-06-17

Affected (1)

VendorProduct
microfocussecure messaging gateway

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD