CVE-2021-35484

High
|8.2
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an authenticated user to exploit a flaw in the Nokia IMPACT system to extract sensitive information from the database, such as user credentials and database details, by manipulating a specific web request. To take advantage of this, the attacker must already have access to the system as a logged-in user.

Technical Description

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References