Mitigation Instructions for CVE-2016-4437
Mitigating CVE-2016-4437: Remote Code Execution Vulnerability in Apache ActiveMQ
1 min read
CyRisk Vulnerability Management Team : Feb 23, 2024 4:39:58 PM
SUBJECT: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
TECH STACK: Web Application (Progress MOVEit Transfer)
DATE(S) ISSUED: 06/16/2023
NVD Last Modified: 06/20/2023
CRITICALITY: CRITICAL
OVERVIEW:
CVE-2023-35708 is a critical vulnerability in Progress MOVEit Transfer versions prior to 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3).
This vulnerability allows an unauthenticated attacker to exploit an SQL injection flaw in the MOVEit Transfer web application, potentially gaining unauthorized access to the database. The attacker could then modify or disclose sensitive database content.
SOLUTION:
Immediate action is required to mitigate this vulnerability:
REFERENCES:
Third Party Advisories:
Confirmation & Additional Information:
Cross-References:
Mitigating CVE-2016-4437: Remote Code Execution Vulnerability in Apache ActiveMQ
Mitigating CVE-2013-1896: Privilege Escalation Vulnerability in Puppet
Subject: Mitigating CVE-2014-6271: Shellshock Vulnerability in Bash