CISA Known Exploited Vulnerability

CVE-2021-27101 Ransomware

Accellion · FTA

Accellion FTA SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89, CWE-138
Ransomware Known

CISA description

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

Required action

Apply updates per vendor instructions.