Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
2017-05-18T06:29:00.217
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ipswitch | moveit_dmz | ≤ 8.1 | Yes |
Application | ipswitch | moveit_dmz | 8.2 | Yes |
Application | ipswitch | moveit_dmz | 8.3 | Yes |
Application | ipswitch | moveit_transfer_2017 | 9.0 | Yes |