← Back

CVE-2020-16104

nvd nist
Published: Dec 14, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.

Affected (13)

1 product
Command Centre
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Gallagher
Before 7.90.0
From 8.00 to 8.00.1228
From 8.10 to 8.10.1211
From 8.20 to 8.20.1166
From 8.30 to 8.30.1236
Version 8.00.1228
Version 8.00.1228 maintenance_release6
Version 8.10.1211
Version 8.10.1211 maintenance_release5
Version 8.20.1166
Version 8.20.1166 maintenance_release3
Version 8.30.1236
Version 8.30.1236 maintenance_release1

References (2)

Source: disclosures@gallagher.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.