BIG-IP Configuration utility에 인증된 SQL 인젝션 취약점이 존재하며, 이로 인해 BIG-IP 관리 포트 및/또는 self IP 주소를 통해 Configuration utility에 네트워크로 접근할 수 있는 인증된 공격자가 임의의 시스템 명령을 실행할 수 있습니다. 참고: 기술 지원 종료(End of Technical Support, EoTS)에 도달한 소프트웨어 버전은 평가되지 않습니다.
BIG-IP Configuration utility에 인증된 SQL 인젝션 취약점이 존재하며, 이로 인해 BIG-IP 관리 포트 및/또는 self IP 주소를 통해 Configuration utility에 네트워크로 접근할 수 있는 인증된 공격자가 임의의 시스템 명령을 실행할 수 있습니다. 참고: 기술 지원 종료(End of Technical Support, EoTS)에 도달한 소프트웨어 버전은 평가되지 않습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated