PT-2024-11748 · Sparx Systems · Enterprise Architect

Maksymilian Kubiak

+1

·

Published

2024-01-31

·

Updated

2024-02-09

·

CVE-2022-47072

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Enterprise Architect version 16.0.1605
Description The issue allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box. This can be exploited by attackers to execute unauthorized SQL queries.
Recommendations For Enterprise Architect version 16.0.1605, consider restricting access to the Select Classifier dialog box until a patch is available. As a temporary workaround, avoid using the Find parameter in the affected dialog box to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-47072

Affected Products

Enterprise Architect