SQL Injection Vulnerability in Symantec Altiris Deployment Solution
CVE-2008-2286

Currently unrated

Key Information:

Vendor

Symantec

Vendor
CVE Published:
18 May 2008

What is CVE-2008-2286?

An SQL injection vulnerability exists in the axengine.exe component of Symantec Altiris Deployment Solution versions 6.8.x and 6.9.x prior to 6.9.176. This flaw enables remote attackers to manipulate SQL queries by injecting malicious commands through unspecified string fields within a notification packet. Successful exploitation of this vulnerability could allow remote attackers to execute arbitrary SQL statements, potentially compromising the integrity and confidentiality of the compromised system.

References

EPSS Score

35% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.