AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-12464

CRITICAL · CVSS 10 EPSS 80.54% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-12464
Severity
CRITICAL
CVSS
10
EPSS
80.54%

Original NVD Description

A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).