PT-2021-21860 · Hexagon · Hexagon Geomedia Webmap 2020

Published

2021-08-30

·

Updated

2021-09-01

·

CVE-2021-37749

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Hexagon GeoMedia WebMap 2020 versions prior to 16.6.2.66
Description: The issue allows blind SQL Injection via the Id parameter within sourceItems to the GetMap method. This can be exploited through the MapService.svc endpoint.
Recommendations: For Hexagon GeoMedia WebMap 2020 versions prior to 16.6.2.66, update to version 16.6.2.66 or later to resolve the issue. As a temporary workaround, consider restricting access to the GetMap method or disabling the Id parameter within sourceItems to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37749

Affected Products

Hexagon Geomedia Webmap 2020