Jive.Openfire.Server.SQL.Injection

description-logoDescription

This indicates an attack attempt against an SQL-injection vulnerability in Openfire.
The vulnerability is caused by an error when the vulnerable software handles sipark-log-summary.jsp. It allows a remote attacker to perform SQL injection via sending a crafted web page.

affected-products-logoAffected Products

Ignite Realtime Openfire 3.6.0a

Impact logoImpact

System Compromise: Remote attackers can inject SQL codes.

recomended-action-logoRecommended Actions

Refer to the vendor's web site for the suggested workaround.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)