Symptoms:
A SQL injection vulnerability in App Broker 2018R1 and earlier allows local users to execute arbitrary SQL commands via the MachineName parameter.
Diagnosis:
The machine name sent by the client is not validated, and can be used to deliver SQL commands that would be interpreted by the database engine.
Steps to Reproduce:
Resolution:
This issue has been resolved in App Broker 2019 R1. Please download the latest version of App Broker 2019 R1 from the PLC download area.
Additional Information:
This issue has been tracked under issue number IOJ-1908386.
For release notes and resolved issues in App Broker 2019 R1, please visit:
https://helpnet.flexerasoftware.com/appportal/rn2019r1/AppPortalAppBroker2019r1ReleaseNotes.htm#resolve
Related Documents:
A copy of the advisory is attached to this article.
Related Articles
Fix Intune sync failure when ConfigMgr sync is enabled in App Broker 2025 R1 5Number of Views App Broker site down. Users unable to access App Broker site. 5Number of Views Created webapi.conf files contain incorrect URLs using the "http" scheme instead of "https" for App Broker to connect to t… 1Number of Views Important Security Updates for On-premise Snow License Manager - Vulnerabilities CVE-2023-3864 and CVE-2023-3937 16Number of Views A list of commonly referenced App Broker database tables 6Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago