RULE(RULE ID:338654)

Rule General Information
Release Date: 2025-01-14
Rule Name: Heimdall Data Leakage Prevention pushSetup.do SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The Heimdall data leak protection system adopts an open architecture and integrates with the existing IT infrastructure, which is an integrated single management platform system. There is SQL injection vulnerability in the pushSetup.do interface of the system. In addition to obtaining information in the database (such as administrator background password, site user personal information) by using the SQL injection vulnerability, the attacker can even write commands to the server under high permission to further obtain the server system permission.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.