PT-2021-22990 · Genesys · Genesys Intelligent Workload Distribution

Gabor Szivos

·

Published

2021-12-08

·

Updated

2021-12-13

·

CVE-2021-40861

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Genesys intelligent Workload Distribution (IWD) version 9.0.017.07
Description A SQL Injection issue in the custom filter query component allows an attacker to execute arbitrary SQL queries via the value attribute. This enables the extraction of all data in the database and potentially allows OS command execution, depending on the permissions and/or database engine.
Recommendations For Genesys intelligent Workload Distribution (IWD) version 9.0.017.07, consider restricting access to the custom filter query component to minimize the risk of exploitation. Avoid using the value attribute in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40861

Affected Products

Genesys Intelligent Workload Distribution