PT-2015-2769 · Emerson · Emerson Ams Device Manager

Publicado

2015-05-25

·

Atualizado

2016-04-06

·

CVE-2015-1008

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Emerson AMS Device Manager versions prior to 13
Description The issue is related to a lack of protection against SQL query structure exploitation, which can be used by a remote attacker to elevate privileges through incorrect data input. This can allow remote authenticated users to gain privileges via malformed input.
Recommendations For Emerson AMS Device Manager versions prior to 13, update to version 13 or later to resolve the issue. As a temporary workaround, consider restricting access to the SQL query functionality to minimize the risk of exploitation. Avoid using malformed input in the affected system until the issue is resolved.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12134
CVE-2015-1008

Produtos afetados

Emerson Ams Device Manager