CVE-2019-18464
Estado: ModificadaCrítica (9.8)—
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the database.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.95%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
- https://community.ipswitch.com/s/article/SQL-Injection-Vulnerability-2
- https://docs.ipswitch.com/MOVEit/Transfer2018SP2/ReleaseNotes/en/index.htm#46490.htm
- https://docs.ipswitch.com/MOVEit/Transfer2019/ReleaseNotes/en/index.htm#48648.htm
- https://docs.ipswitch.com/MOVEit/Transfer2019_1/ReleaseNotes/en/index.htm#49443.htm
- https://community.ipswitch.com/s/article/SQL-Injection-Vulnerability-2
- https://docs.ipswitch.com/MOVEit/Transfer2018SP2/ReleaseNotes/en/index.htm#46490.htm
- https://docs.ipswitch.com/MOVEit/Transfer2019/ReleaseNotes/en/index.htm#48648.htm
- https://docs.ipswitch.com/MOVEit/Transfer2019_1/ReleaseNotes/en/index.htm#49443.htm
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-18464",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-10-31T17:15:10.400",
"references": [
{
"url": "https://community.ipswitch.com/s/article/SQL-Injection-Vulnerability-2",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.ipswitch.com/MOVEit/Transfer2018SP2/ReleaseNotes/en/index.htm#46490.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.ipswitch.com/MOVEit/Transfer2019/ReleaseNotes/en/index.htm#48648.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.ipswitch.com/MOVEit/Transfer2019_1/ReleaseNotes/en/index.htm#49443.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://community.ipswitch.com/s/article/SQL-Injection-Vulnerability-2",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.ipswitch.com/MOVEit/Transfer2018SP2/ReleaseNotes/en/index.htm#46490.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.ipswitch.com/MOVEit/Transfer2019/ReleaseNotes/en/index.htm#48648.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.ipswitch.com/MOVEit/Transfer2019_1/ReleaseNotes/en/index.htm#49443.htm",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the database."
},
{
"lang": "es",
"value": "En Progress MOVEit Transfer versiones 10.2 anteriores a 10.2.6 (2018.3), versiones 11.0 anteriores a 11.0.4 (2019.0.4) y versiones 11.1 anteriores a 11.1.3 (2019.1.3), se han encontrado múltiples vulnerabilidades de inyección SQL en la API REST que podrían permitir a un atacante no autenticado conseguir acceso no autorizado a la base de datos. Dependiendo del motor de base de datos que está siendo usado (MySQL, Microsoft SQL Server o Azure SQL), un atacante puede ser capaz de inferir información sobre la estructura y el contenido de la base de datos o puede ser capaz de alterar la base de datos."
}
],
"lastModified": "2026-06-17T02:25:04.103",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ipswitch:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A2744B6-A5D5-4B18-8044-F9DCF7F26F67",
"versionEndExcluding": "10.2.6",
"versionStartIncluding": "10.2.0"
},
{
"criteria": "cpe:2.3:a:ipswitch:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9AAF086-01CC-4FEF-B92E-2BF355420B1B",
"versionEndExcluding": "11.0.4",
"versionStartIncluding": "11.0"
},
{
"criteria": "cpe:2.3:a:ipswitch:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBFF54A6-F11C-4EDE-A023-DDF56F61E857",
"versionEndExcluding": "11.1.3",
"versionStartIncluding": "11.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}