Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nokia:impact:*:*:*:*:*:*:*:* |
Wed, 04 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia impact |
|
| Vendors & Products |
Nokia
Nokia impact |
Tue, 03 Mar 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-03-03T00:00:00.000Z
Updated: 2026-03-04T15:10:45.811Z
Reserved: 2021-06-24T00:00:00.000Z
Link: CVE-2021-35484
Updated: 2026-03-04T15:08:26.436Z
Status : Analyzed
Published: 2026-03-03T18:16:20.770
Modified: 2026-03-05T21:53:00.810
Link: CVE-2021-35484
No data.