CVE-2015-8261: Progress WhatsUp Gold
Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.
Affected products
- Progress WhatsUp Gold: version 16.3 only
Published 2016-01-08. Last modified 2026-06-17.