A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.
2022-01-11T12:15:09.930
2024-11-21T06:14:50.547
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | siemens | comos | ≤ 10.2 | Yes |
| Application | siemens | comos | < 10.3.3.3 | Yes |
| Application | siemens | comos | 10.4 | Yes |