SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36055 | SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Fixes
Solution
Upgrade to version 23.3.38 build 19. Apply configuration changes per https://documentation.sysaid.com/classic/docs/sql-sanitizer https://mcas-proxyweb.mcas.ms/certificate-checker
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-08-02T03:37:04.931Z
Reserved: 2024-05-27T13:04:44.111Z
Link: CVE-2024-36393
Updated: 2024-08-02T03:37:04.931Z
Status : Modified
Published: 2024-06-06T09:15:14.420
Modified: 2024-11-21T09:22:05.170
Link: CVE-2024-36393
No data.
OpenCVE Enrichment
No data.
EUVD