PT-2025-3125 · Polaris Ft · Polaris Ft Intellect Core Banking

Nguyen Hong Phuc

·

Published

2025-01-08

·

Updated

2025-01-08

·

CVE-2024-55517

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Polaris FT Intellect Core Banking version 9.5
Description An issue was discovered in the Interllect Core Search, where input passed through the groupType parameter in "/SCGController" is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session.
Recommendations For Polaris FT Intellect Core Banking version 9.5, as a temporary workaround, consider restricting access to the /SCGController endpoint or disabling the use of the groupType parameter until a patch is available. Avoid using the groupType parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-55517

Affected Products

Polaris Ft Intellect Core Banking