CVE-2021-37197

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGH
EPSS
0.4%
top 37.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11
Latest updateFeb 10

Description

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDsiemens/comos10.310.3.3.3+2
CVEListV5siemens/comos_v10.2All versions only if web components are used
CVEListV5siemens/comos_v10.3All versions < V10.3.3.3 only if web components are used
CVEListV5siemens/comos_v10.4All versions < V10.4.1 only if web components are used

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v3m2-hfqm-f87x: A vulnerability has been identified in COMOS (All versions < V102022-02-10
CVEList
CVE-2021-37197: A vulnerability has been identified in COMOS V102022-01-11