CVE-2018-15904

A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
a10networksacos_web_application_firewall
2.7.1
a10networksacos_web_application_firewall
2.7.2
a10networksacos_web_application_firewall
2.7.2:p1
a10networksacos_web_application_firewall
2.7.2:p10
a10networksacos_web_application_firewall
2.7.2:p11
a10networksacos_web_application_firewall
2.7.2:p2
a10networksacos_web_application_firewall
2.7.2:p3
a10networksacos_web_application_firewall
2.7.2:p4
a10networksacos_web_application_firewall
2.7.2:p5
a10networksacos_web_application_firewall
2.7.2:p6
a10networksacos_web_application_firewall
2.7.2:p7
a10networksacos_web_application_firewall
2.7.2:p7-sp3
a10networksacos_web_application_firewall
2.7.2:p8
a10networksacos_web_application_firewall
2.7.2:p9
a10networksacos_web_application_firewall
4.1.0
a10networksacos_web_application_firewall
4.1.0:p1
a10networksacos_web_application_firewall
4.1.0:p10
a10networksacos_web_application_firewall
4.1.0:p2
a10networksacos_web_application_firewall
4.1.0:p3
a10networksacos_web_application_firewall
4.1.0:p4
a10networksacos_web_application_firewall
4.1.0:p5
a10networksacos_web_application_firewall
4.1.0:p6
a10networksacos_web_application_firewall
4.1.0:p7
a10networksacos_web_application_firewall
4.1.0:p8
a10networksacos_web_application_firewall
4.1.0:p9
a10networksacos_web_application_firewall
4.1.1
a10networksacos_web_application_firewall
4.1.1:p1
a10networksacos_web_application_firewall
4.1.1:p2
a10networksacos_web_application_firewall
4.1.1:p3
a10networksacos_web_application_firewall
4.1.1:p4
a10networksacos_web_application_firewall
4.1.1:p5
a10networksacos_web_application_firewall
4.1.1:p6
a10networksacos_web_application_firewall
4.1.1:p7
a10networksacos_web_application_firewall
4.1.2
a10networksacos_web_application_firewall
4.1.2:p1
a10networksacos_web_application_firewall
4.1.2:p2
a10networksacos_web_application_firewall
4.1.2:p3
𝑥
= Vulnerable software versions