CVE-2022-45165

An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:archibus:web_central:2022.03.01.107:*:*:*:*:*:*:*

History

21 Nov 2024, 07:28

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Archibus Web Central 2022.03.01.107. Un servicio expuesto por la aplicación acepta un parámetro controlado por el usuario que se utiliza para crear una consulta SQL. Hace que este servicio sea propenso a la inyección de SQL.
References () https://excellium-services.com/cert-xlm-advisory/CVE-2022-45165/ - Third Party Advisory () https://excellium-services.com/cert-xlm-advisory/CVE-2022-45165/ - Third Party Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 6.5

Information

Published : 2023-01-10 21:15

Updated : 2025-04-09 16:15


NVD link : CVE-2022-45165

Mitre link : CVE-2022-45165

CVE.ORG link : CVE-2022-45165


JSON object : View

Products Affected

archibus

  • web_central
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')