PT-2020-17259 · Keysight+1 · Keysight Database Connector+1

Published

2020-12-15

·

Updated

2020-12-17

·

CVE-2020-35122

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keysight Database Connector plugin versions prior to 1.5.0 for Confluence
Description An issue was discovered in the Keysight Database Connector plugin for Confluence, where a malicious user could bypass access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the database connection profiles to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35122

Affected Products

Confluence
Keysight Database Connector