Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
History

Tue, 03 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
Description Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-03T17:28:34.345Z

Reserved: 2021-06-24T00:00:00.000Z

Link: CVE-2021-35484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-03T18:16:20.770

Modified: 2026-03-03T18:16:20.770

Link: CVE-2021-35484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.