Description
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 23.3.38 build 19. Apply configuration changes per https://documentation.sysaid.com/classic/docs/sql-sanitizer https://mcas-proxyweb.mcas.ms/certificate-checker
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36056 | SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: INCD
Published:
Updated: 2024-08-02T03:37:05.138Z
Reserved: 2024-05-27T13:04:44.111Z
Link: CVE-2024-36394
Updated: 2024-08-02T03:37:05.138Z
Status : Modified
Published: 2024-06-06T09:15:14.660
Modified: 2024-11-21T09:22:05.317
Link: CVE-2024-36394
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD