SQL Injection in Symphony Plus
Published Dec 22, 2020
9.8
CRITICALCVSS 3.1
EPSS 1.10%
Description
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. This can lead to a loss of confidentiality and data integrity or even affect the product behavior and its availability.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<3.2
- Version
-
- Version unspecifiedStatusaffectedConstraints<2.1 SP2 Rollup 2
- Version unspecifiedStatusaffectedConstraints<2.2
- Version unspecifiedStatusaffectedConstraints<3.3 Service Pack 1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ABB | ABB Ability™ Symphony® Plus Historian | n/a |
| ||||||||||||
| ABB | ABB Ability™ Symphony® Plus Operations | n/a |
|
- 3.0
- 3.1
- 1.1
- 2.0
- 2.1
- 2.1
- 3.0
- 3.1
- 3.2
- 3.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-17387 Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch x_refsource_MISCMitigationVendor Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch x_refsource_MISCMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-17387 | Advisory | |
| https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch | x_refsource_MISCMitigationVendor Advisory | |
| https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch | x_refsource_MISCMitigationVendor Advisory |
Change history (0)
No recorded changes yet.