CVE Published: 20/07/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: twcert |
Vendor: Data Systems Consulting Co., Ltd. |
Product: BPM Status : PUBLISHED
CVE-2022-32456 Description
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H