Lucene search

K
ibmIBMDFA29A725476D79BF79FFA8201BC4476D6E19EC106B227F00413B37555F85385
HistoryJun 30, 2021 - 10:41 a.m.

Security Bulletin: SQL injection from various input fields may affect Datacap Navigator

2021-06-3010:41:18
www.ibm.com
15
sql injection
datacap navigator
ibm
vulnerability
cve-2020-4902
security testing

EPSS

0.001

Percentile

43.2%

Summary

In Security testing found that SQL injection from various input fields may affect Datacap Navigator.

Vulnerability Details

CVEID:CVE-2020-4902
**DESCRIPTION:**IBM Datacap Taskmaster Capture is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/191045 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
Datacap Navigator 9.1.7

Remediation/Fixes

** Product**

|

** VRMF**

|

** Remediation/First Fix**

—|—|—

Datacap Navigator

|

9.1.8

|

Upgrade to 9.1.8 iFix 001, available from Fix Central

Workarounds and Mitigations

None

EPSS

0.001

Percentile

43.2%

Related for DFA29A725476D79BF79FFA8201BC4476D6E19EC106B227F00413B37555F85385