CVE-2018-10593: SQL Injection
A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in data corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity level of CVE-2018-10593?
The severity level of CVE-2018-10593 is medium with a score of 5.6.
Which software versions are affected by CVE-2018-10593?
DB Manager version 3.0.1.0 and previous, and PerformA version 3.0.0.0 and previous are affected by CVE-2018-10593.
What can an authorized user with access to a privileged account do with CVE-2018-10593?
An authorized user with access to a privileged account can issue SQL commands, which may result in data corruption or other unauthorized actions.
Are the InoqulA+, Kiestra TLA, and Kiestra WCA systems vulnerable to CVE-2018-10593?
No, the InoqulA+, Kiestra TLA, and Kiestra WCA systems are not vulnerable to CVE-2018-10593.
How can I fix CVE-2018-10593?
To fix CVE-2018-10593, it is recommended to update DB Manager and PerformA to the latest versions provided by BD.