Back

CVE-2018-12464

CRITICAL

A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).

Published: Jun 29, 2018 Modified: Jun 17, 2026
CWE-89 CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
microfocus secure_messaging_gateway * < 471

GitHub Security Advisory GHSA-qx98-cwxc-vrv6

A SQL injection vulnerability in the web administration and quarantine components of Micro Focus...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 80.67%

Top 0% most likely to be exploited

Threat Score 74.2 / 100

Data Sources

NVD EPSS GitHub