The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50253 The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.
Fixes

Solution

Update Service Pack to version v5.3.1 or later.


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Newtype
Newtype flowmaster Bpm Plus
CPEs cpe:2.3:a:newtype:flowmaster_bpm_plus:*:*:*:*:*:*:*:*
Vendors & Products Newtype
Newtype flowmaster Bpm Plus

Tue, 15 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared New Type
New Type flowmaster Bpm Plus
CPEs cpe:2.3:a:new_type:flowmaster_bpm_plus:*:*:*:*:*:*:*:*
Vendors & Products New Type
New Type flowmaster Bpm Plus
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 04:00:00 +0000

Type Values Removed Values Added
Description The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.
Title NewType FlowMaster BPM Plus - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-10-15T14:05:33.351Z

Reserved: 2024-10-15T01:57:24.052Z

Link: CVE-2024-9971

cve-icon Vulnrichment

Updated: 2024-10-15T14:05:28.315Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T04:15:05.080

Modified: 2024-10-17T20:34:30.257

Link: CVE-2024-9971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.