Описание
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.
Ссылки
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.0.0 (включая)Версия до 1.1.0.2 (включая)
Одновременно
Одно из
cpe:2.3:a:bd:database_manager:3.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:bd:performa:*:*:*:*:*:*:*:*
cpe:2.3:a:bd:reada:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:bd:inoqula\+:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:kiestra_tla:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:kiestra_wca:-:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00209
Низкий
6.3 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-356
CWE-89
Связанные уязвимости
CVSS3: 6.3
github
больше 3 лет назад
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.
EPSS
Процентиль: 43%
0.00209
Низкий
6.3 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-356
CWE-89