CVE-2018-10595: SQL Injection
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10595?
The severity of CVE-2018-10595 is medium with a severity value of 6.3.
Which software versions are affected by CVE-2018-10595?
CVE-2018-10595 affects ReadA version 1.1.0.2 and previous, Bd Database Manager version 3.0.1.0, and Bd Performa version up to 3.0.0.0.
What is the impact of CVE-2018-10595?
CVE-2018-10595 allows an authorized user with access to a privileged account on a BD Kiestra system to issue SQL commands, which may result in loss or corruption of data.
How can I fix CVE-2018-10595?
To fix CVE-2018-10595, it is recommended to update to a patched version of ReadA, Bd Database Manager, or Bd Performa as advised by the product security bulletin.
Where can I find more information about CVE-2018-10595?
You can find more information about CVE-2018-10595 in the ICS-CERT advisory (https://ics-cert.us-cert.gov/advisories/ICSMA-18-142-01) and the product security bulletin by BD (https://www.bd.com/en-us/support/product-security-and-privacy/product-security-bulletin-bd-kiestra-tla-bd-kiestra-wca-bd-inoqula).