First published: Thu May 24 2018(Updated: )
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Bd Database Manager | =3.0.1.0 | |
Bd Performa | <=3.0.0.0 | |
Bd Reada | <=1.1.0.2 | |
Bd Inoqula\+ | ||
Bd Kiestra Tla | ||
Bd Kiestra Wca |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10595 is medium with a severity value of 6.3.
CVE-2018-10595 affects ReadA version 1.1.0.2 and previous, Bd Database Manager version 3.0.1.0, and Bd Performa version up to 3.0.0.0.
CVE-2018-10595 allows an authorized user with access to a privileged account on a BD Kiestra system to issue SQL commands, which may result in loss or corruption of data.
To fix CVE-2018-10595, it is recommended to update to a patched version of ReadA, Bd Database Manager, or Bd Performa as advised by the product security bulletin.
You can find more information about CVE-2018-10595 in the ICS-CERT advisory (https://ics-cert.us-cert.gov/advisories/ICSMA-18-142-01) and the product security bulletin by BD (https://www.bd.com/en-us/support/product-security-and-privacy/product-security-bulletin-bd-kiestra-tla-bd-kiestra-wca-bd-inoqula).