CVE-2017-15367 describes multiple critical SQL Injection vulnerabilities in Bacula-web versions prior to 8.0.0-rc2. This flaw allows unauthenticated attackers to remotely access the Bacula database and potentially escalate privileges on the server, as indicated by its CVSS score of 9.8. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, and the vulnerability has garnered significant community discussion, suggesting a heightened risk of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.4.0CPE matchmatch criteria | cpe:2.3:a:bacula:bacula-web:*:*:*:*:*:*:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:bacula:bacula-web:8.0.0:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.