Impact
Improper neutralization of special elements used in an SQL command creates a SQL injection flaw in Iron Mountain Archiving Services Inc.'s enVision. The flaw allows an attacker to inject arbitrary SQL statements, potentially compromising the confidentiality, integrity, or availability of the underlying database. The specific weakness is a classic SQL injection (CWE‑89).
Affected Systems
Iron Mountain Archiving Services Inc. offers the enVision archiving platform. Versions of enVision prior to build 260655 are affected and therefore require attention.
Risk and Exploitability
The CVSS score of 8.8 indicates high risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not detailed in the report, it is inferred that the vulnerability can be exercised via web inputs that are incorporated into SQL statements without proper sanitization. An attacker with access to the application interface could potentially execute arbitrary SQL commands against the backend database.
OpenCVE Enrichment