RULE(RULE ID:711207)

Rule General Information
Release Date: 2017-07-17
Rule Name: WEB-SQL-INJECTION HPE Network Automation Redirectservlet SQL Injection Vulnerability (CVE-2017-5810)
Severity:
CVE ID:
Rule Protection Details
Description: A SQL injection vulnerability was found in in HPE Network Automation. The vulnerability is caused by deficient sanitization of certain HTTP request parameters in RedirectServlet.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference:
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03740en_us