Keeping WhatsUp Gold Secure
Hey folks, this is Brian M. Jacobs, Senior Product Manager for the WhatsUp Gold family of network management products. I would like to let you know that a security researcher (who has been a big fan of WhatsUp Gold for many years) has informed us of a SQL injection vulnerability in the WhatsUp Gold v15.0.2 product. This vulnerability involves WhatsUp Gold running in a default deployment, in which administrators have privileged access to the database instance. For customers who wish to restrict access to their database, we already provide the capability to configure WhatsUp Gold to run with reduced database privileges. Details on how to implement reduced privilege operation can be found in our Database Migration and Management Guide. Based on our customers' input, we are also working on security patches to limit all SQL injection related vulnerabilities, regardless of database privilege level.