Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia impact |
|
| Vendors & Products |
Nokia
Nokia impact |
Tue, 03 Mar 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-03-03T00:00:00.000Z
Updated: 2026-03-04T15:10:45.811Z
Reserved: 2021-06-24T00:00:00.000Z
Link: CVE-2021-35484
Updated: 2026-03-04T15:08:26.436Z
Status : Undergoing Analysis
Published: 2026-03-03T18:16:20.770
Modified: 2026-03-04T16:16:23.107
Link: CVE-2021-35484
No data.