← back
CVE-2017-3899

CVE-2017-3899

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.7%
exploitation probability
1.7%top 24% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Intel Security Advanced Threat Defense allows authenticated users to inject malicious SQL code through a web request, potentially exposing sensitive product information.

Technical detail

SQL injection vulnerability in ATD Linux 3.6.0 and earlier exists in HTTP request parameter handling. An authenticated attacker can craft malicious SQL queries to extract product data from the backend database without proper input sanitization.

Summary generated and translated by AI from the official description.
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.