CVE-2017-12567

SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
questkace_asset_management_appliance
6.4.120822
questkace_asset_management_appliance
7.0
questkace_asset_management_appliance
7.0.121306
questkace_asset_management_appliance
7.1
questkace_asset_management_appliance
7.1.149
questkace_asset_management_appliance
7.2
questkace_systems_management_appliance
6.4.120822
questkace_systems_management_appliance
7.0
questkace_systems_management_appliance
7.0.121306
questkace_systems_management_appliance
7.1
questkace_systems_management_appliance
7.1.149
questkace_systems_management_appliance
7.2
questkace_systems_management_appliance
7.2.101
questk1000_as_a_service
7.0
questk1000_as_a_service
7.0.121306
questk1000_as_a_service
7.1
questk1000_as_a_service
7.1.149
questk1000_as_a_service
7.2
𝑥
= Vulnerable software versions