← Back

CVE-2021-40861

nvd nist
Published: Dec 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

Affected (1)

1 product
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 9.0.013.11 to 9.0.017.07

References (4)

Source: cve@mitre.org
ProductRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease NotesVendor Advisory

Timeline

No history available yet.