CVE-2021-35484
HIGHNokia IMPACT <19.11.2.10 - SQL Injection
Title source: llmDescription
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
Scores
CVSS v3
8.2
EPSS
0.0003
EPSS Percentile
8.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Classification
CWE
CWE-89
Status
published
Affected Products (1)
nokia/impact
< 19.11.2.10-20210118042150283
Timeline
Published
Mar 03, 2026
Tracked Since
Mar 04, 2026