Lucene search

K
cvelistMitreCVELIST:CVE-2021-40861
HistoryDec 08, 2021 - 2:58 p.m.

CVE-2021-40861

2021-12-0814:58:13
mitre
www.cve.org
1
sql injection
genesys iwd
arbitrary sql queries
database extraction
os command execution

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

34.3%

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

34.3%

Related for CVELIST:CVE-2021-40861