98 lines
2.6 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2022-32964",
"sourceIdentifier": "twcert@cert.org.tw",
"published": "2022-08-04T10:15:08.190",
"lastModified": "2022-10-26T02:48:32.853",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "OMICARD EDM\u2019s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service."
},
{
"lang": "es",
"value": "La funci\u00f3n de la API de OMICARD EDM no comprueba suficientemente las entradas del usuario. Un atacante remoto no autenticado puede inyectar comandos SQL arbitrarios para acceder, modificar, eliminar la base de datos o interrumpir el servicio"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "twcert@cert.org.tw",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"source": "twcert@cert.org.tw",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:omicard_edm_project:omicard_edm:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.8",
"versionEndIncluding": "6.0",
"matchCriteriaId": "F11B29BF-543C-4268-B257-E02275F6B969"
}
]
}
]
}
],
"references": [
{
"url": "https://www.chtsecurity.com/news/48032532-b2de-401c-97a8-a2be5691988f",
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.twcert.org.tw/tw/cp-132-6372-f61bc-1.html",
"source": "twcert@cert.org.tw",
"tags": [
"Third Party Advisory"
]
}
]
}