PT-2020-13165 · Microsoft+1 · Sql Server+1
Pablo Martinez
+1
·
Published
2020-08-17
·
Updated
2020-08-21
·
CVE-2020-12606
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DB Soft SGLAC versions prior to 20.05.001
Description
An issue in the SGLAC web frontend allows an attacker to execute arbitrary SQL commands on the SQL Server. This can be achieved by using the
xp cmdshell stored procedure through the ProcedimientoGenerico method in the SVCManejador.svc webservice.Recommendations
For versions prior to 20.05.001, update to version 20.05.001 or later to resolve the issue. As a temporary workaround, consider restricting access to the
SVCManejador.svc webservice to minimize the risk of exploitation. Avoid using the xp cmdshell stored procedure in the affected SQL Server until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sglac
Sql Server