An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by the TableName, ColumnName, Name, UserId, or Password parameter.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHyland Onbase
APPHyland≤ 16.0.2.8317.0.0.0 – 17.0.2.10918.0.0.0 – 18.0.0.3719.0.0.0 – 19.8.16.100020.0.0.0 – 20.3.10.1000
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2020-25256CRITICAL9.1PL ✓same product
Hyland OnBase — wspólny klucz prywatny PKI we wszystkich instalacjach
CVE-2020-25257CRITICAL9.8PL ✓same product
XXE w Hyland OnBase — nieautoryzowany odczyt i zapis plików
CVE-2020-25254CRITICAL9.8PL ✓same product
SQL injection w Hyland OnBase — nieautoryzowany dostęp do bazy danych
CVE-2020-25251CRITICAL9.1PL ✓same product
Hyland OnBase — pominięcie uwierzytelnienia (Auth Bypass) po stronie klienta
CVE-2020-25258CRITICAL9.8PL ✓same product
Zdalne wykonanie kodu przez niebezpieczną deserializację w Hyland OnBase