Dimension SQL Injection in Audit Report
Summary #
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Impact: An authenticated Dimension administrator can exploit the SQL injection to execute stacked SQL statements with PostgreSQL superuser privileges, read and write arbitrary files within the database process's permissions, and achieve operating system command execution as the wgadmin service user by planting a malicious server-side session file that is later deserialized. This results in full compromise of confidentiality, integrity, and availability of the Dimension appliance.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
Solution #
References #
Credits #
- Yukusawa18finder