CVE-2021-35484
8.2Nokia · IMPACT
Nokia IMPACT allows an authenticated user to perform a Time-based Boolean Blind SQL injection via the sortColumn parameter on the /ui/rest-proxy/campaign/statistic endpoint.
Executive summary
An authenticated SQL injection vulnerability in the Nokia IMPACT platform allows attackers to extract sensitive database information and gain unauthorized insight into system configurations.
Vulnerability
This is a Time-based Boolean Blind SQL injection flaw located in the sortColumn HTTP GET parameter. While the original description suggested unauthenticated access, the authoritative enrichment confirms that an authenticated user can trigger this vulnerability to exfiltrate database user, name, and version details.
Business impact
Successful exploitation of this SQL injection vulnerability allows an attacker to gain unauthorized access to sensitive database contents. This could lead to a compromise of system integrity and potential exposure of proprietary operational data. With a CVSS score of 8.2, this vulnerability represents a high risk to organizational security and data confidentiality.
Remediation
Immediate Action: Contact your Nokia support representative to obtain the specific security update or configuration patch that addresses this SQL injection vulnerability in the IMPACT platform.
Proactive Monitoring: Review web server and application access logs for anomalous GET requests containing suspicious characters or abnormal timing patterns in the sortColumn parameter.
Compensating Controls: Implement a Web Application Firewall (WAF) to inspect incoming traffic and block requests containing SQL syntax patterns targeted at the /ui/rest-proxy/campaign/statistic endpoint.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS severity, administrators should prioritize the identification of affected Nokia IMPACT deployments. Engage with the vendor immediately to confirm available patches and ensure that user access controls are strictly enforced to minimize the risk of unauthorized exploitation until the vulnerability is fully remediated.