PT-2022-11907 · Odyssey · Odyssey

Published

2022-08-25

·

Updated

2022-10-14

·

CVE-2021-43766

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Odyssey (affected versions not specified)
Description The issue allows a man-in-the-middle attacker to inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This occurs when Odyssey is configured to use certificate Common Name for client authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2021-43766

Affected Products

Odyssey