CVE-2015-3423: Netcracker Resource Management System

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9) filter_INSERT_COUNT, (10) filter_MINOR_FALLOUT, (11) filter_UPDATE_COUNT, (12) sort, or (13) sessid parameter.

Affected products

  • Netcracker Resource Management System: before 8.2 (fixed in 8.2)

Published 2020-02-08. Last modified 2026-06-17.