PT-2019-9373 · Cimtechniques · Cimscan

Published

2019-01-10

·

Updated

2020-01-16

·

CVE-2018-16803

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CIMTechniques CIMScan versions 6.x through 6.2
Description The issue in CIMTechniques CIMScan allows attackers to execute SQL code through the SOAP WSDL parser.
Recommendations For versions 6.x through 6.2, update to a version that includes a fix for this issue, as using the current version may allow attackers to execute SQL code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16803

Affected Products

Cimscan