High severity8.2NVD Advisory· Published Mar 3, 2026· Updated Jun 17, 2026
CVE-2021-35484
CVE-2021-35484
Description
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- www.gruppotim.it/it/footer/red-team/2021/Motive-Impact-CVE-2021-35484.htmlnvdThird Party Advisory
- www.nokia.com/networks/solutions/impact-iot-platform/nvdProduct
- www.nokia.com/notices/responsible-disclosure/nvdIssue Tracking
News mentions
0No linked articles in our index yet.