• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
sonicwall issues patch for critical bug affecting its analytics and

SonicWall Issues Patch for Critical Bug Affecting its Analytics and GMS Products

You are here: Home / General Cyber Security News / SonicWall Issues Patch for Critical Bug Affecting its Analytics and GMS Products
July 22, 2022

Network security enterprise SonicWall on Friday rolled out fixes to mitigate a critical SQL injection (SQLi) vulnerability impacting its Analytics On-Prem and Global Administration Procedure (GMS) merchandise.

The vulnerability, tracked as CVE-2022-22280, is rated 9.4 for severity on the CVSS scoring technique and stems from what the enterprise describes is an “improper neutralization of particular aspects” utilised in an SQL command that could direct to an unauthenticated SQL injection.

CyberSecurity

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“With out ample elimination or quoting of SQL syntax in consumer-controllable inputs, the produced SQL query can result in those people inputs to be interpreted as SQL as a substitute of regular user details,” MITRE notes in its description of SQL injection.

SonicWall

“This can be utilized to change query logic to bypass security checks, or to insert extra statements that modify the back-conclude database, probably which include execution of system commands.”

H4lo and Catalpa of DBappSecurity HAT Lab have been credited with getting and reporting the flaws which have an affect on 2.5..3-2520 and previously variations of Analytics On-Prem as properly as all variations of GMS prior to and like 9.3.1-SP2-Hotfix1.

CyberSecurity

Corporations relying on susceptible appliances are recommended to upgrade to Analytics 2.5..3-2520-Hotfix1 and GMS 9.3.1-SP2-Hotfix-2.

“There is no workaround out there for this vulnerability,” SonicWall reported. “Having said that, the chance of exploitation may be appreciably diminished by incorporating a Web Software Firewall (WAF) to block SQLi attempts.”

Discovered this article appealing? Observe THN on Fb, Twitter  and LinkedIn to read through more exceptional content we put up.


Some parts of this write-up are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Malware-as-a-Service Creating New Cybercrime Ecosystem
Next Post: Roaming Mantis Financial Hackers Targeting Android and iPhone Users in France Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.