In Security testing found that SQL injection from various input fields may affect Datacap Navigator.
CVEID:CVE-2020-4902
**DESCRIPTION:**IBM Datacap Taskmaster Capture is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191045 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)
Affected Product(s) | Version(s) |
---|---|
Datacap Navigator | 9.1.7 |
** Product**
|
** VRMF**
|
** Remediation/First Fix**
—|—|—
Datacap Navigator
|
9.1.8
|
Upgrade to 9.1.8 iFix 001, available from Fix Central
None