SQL Injection Vulnerability in Symantec Altiris Deployment Solution
CVE-2008-2286

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
18 May 2008

Summary

An SQL injection vulnerability exists in the axengine.exe component of Symantec Altiris Deployment Solution versions 6.8.x and 6.9.x prior to 6.9.176. This flaw enables remote attackers to manipulate SQL queries by injecting malicious commands through unspecified string fields within a notification packet. Successful exploitation of this vulnerability could allow remote attackers to execute arbitrary SQL statements, potentially compromising the integrity and confidentiality of the compromised system.

References

EPSS Score

35% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.