Release date: 2012-03-14
Updated on:
Affected Systems:
F5 FirePass 7.0
F5 FirePass 6.1
F5 FirePass 6.0.3
F5 FirePass 6.0.2
F5 FirePass 6.0.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52653
F5 FirePass ssl vpn device allows users to Securely connect to key business application devices.
F5 has the SQL injection vulnerability in FirePass implementation. After successful exploitation, unverified attackers can control the application, access or modify data.
<* Source: F5
Link: http://support.f5.com/kb/en-us/solutions/public/13000/400/sol13463.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
F5
--
F5 has released a Security Bulletin (SOL13463) and corresponding patches for this:
SOL13463: FirePass SQL injection vulnerability
Link: http://support.f5.com/kb/en-us/solutions/public/13000/400/sol13463.html