Impact
The vulnerability is a classic SQL Injection flaw in several REST API query parameters of Brocade SANnav. An attacker who is already authenticated can inject arbitrary SQL statements, potentially reading, modifying, or deleting sensitive data stored in the system’s database. This weakness, classified as CWE-89, presents a moderate risk to confidentiality and integrity, as it allows manipulation of the backend database through crafted inputs.
Affected Systems
The affected product is Brocade SANnav, versions prior to 3.0.0a. All deployments running 3.0.0a or 3.0.1 include the security fix and are no longer vulnerable.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The flaw requires the attacker to be authenticated and to access the exposed REST API endpoints, making it likely to be exploited in environments where API credentials are compromised or poorly secured. The impact is limited to systems that expose these APIs and store critical data accessible via the backend database.
OpenCVE Enrichment