Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44363
HistoryNov 23, 2023 - 9:16 a.m.

SQL Injection

2023-11-2309:16:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
sql injection
submarine server
database
sysdeptmapper.xml
login security

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

Low

EPSS

0.006

Percentile

78.5%

Submarine Server Database is vulnerable to SQL Injection. The vulnerability exists due to improper SQL sanitization in SysDeptMapper.xml which allows an attacker to execute arbitrary SQL queries during login and gain access to sensitive data.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

Low

EPSS

0.006

Percentile

78.5%

Related for VERACODE:44363