SQL Injection Vulnerability in Camstar Enterprise Platform and Opcenter Execution Core

SQL Injection Vulnerability in Camstar Enterprise Platform and Opcenter Execution Core

CVE-2020-7577 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Through the use of several vulnerable fields of the application, an authenticated user could perform an SQL Injection attack by passing a modified SQL query downstream to the back-end server. The exploit of this vulnerability could be used to read, and potentially modify application data to which the user has access to.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.