Some users may experience issues accessing the case portal. For more information, please click here.

App Broker Knowledge Base

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

App Broker Knowledge Base

MachineName Parameter can be used to Exploit a SQL Injection Vulnerability in App Broker

1 0 1107
Symptoms: A SQL injection vulnerability in App Broker 2018R1 and earlier allows local users to execute arbitrary SQL commands via the MachineName parameter. Diagnosis: The machine name sent by the client is not validated, and can be used to deliv...
by Level 7 Flexeran RDanailov Level 7 Flexeran