PT-2022-22013 · Dataease · Dataease

Ryze-T

·

Published

2022-07-22

·

Updated

2022-10-27

·

CVE-2022-34115

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataEase version 1.11.1
Description The issue is related to a SQL injection vulnerability. It occurs via the parameter dataSourceId. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For DataEase version 1.11.1, update to version 1.11.2 to resolve the issue. As a temporary workaround, consider restricting access to the dataSourceId parameter to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-34115
GHSA-VJMR-6PMM-RPRF

Affected Products

Dataease