PT-2025-22542 · Unknown · Matrix Series+2

Published

2025-05-22

·

Updated

2025-05-22

·

CVE-2024-13955

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASPECT-Enterprise versions through 3.* NEXUS Series versions through 3.* MATRIX Series versions through 3.*
Description 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised. This issue potentially grants unauthorized database access.
Recommendations For ASPECT-Enterprise versions through 3., consider restricting access to the database repositories to minimize the risk of exploitation. For NEXUS Series versions through 3., avoid using compromised administrator credentials to prevent unintended access. For MATRIX Series versions through 3.*, restrict access to sensitive database areas until a fix is available. As a temporary workaround, consider disabling access to sensitive database repositories for all affected series until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-13955

Affected Products

Aspect-Enterprise
Matrix Series
Nexus Series