vendor:
EAM
by:
N/A
8,8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: EAM
Affected Version From: V11.0 Build 201410
Affected Version To: V11.0 Build 201410
Patch Exists: YES
Related CWE: CVE-2017-7952
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
SQL injection in INFOR EAM V11.0 Build 201410 search fields (web/base/..) via filtervalue parameter
This vulnerability allows full database access. It includes sensitive information that normally should be accessed by specific users. An attacker could dump the user table, which contains usernames and password hashes, and proceed to bruteforcing passwords offline and could possibly obtain administrative credentials, or could access private files or personal details such as: telephone numbers, physical address and private assets.
Mitigation:
The vendor released a patch to address this vulnerability.