First published: Mon Dec 14 2020(Updated: )
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <7.90.0 | |
Gallagher Command Centre | >=8.00<8.00.1228 | |
Gallagher Command Centre | >=8.10<8.10.1211 | |
Gallagher Command Centre | >=8.20<8.20.1166 | |
Gallagher Command Centre | >=8.30<8.30.1236 | |
Gallagher Command Centre | =8.00.1228 | |
Gallagher Command Centre | =8.00.1228-maintenance_release6 | |
Gallagher Command Centre | =8.10.1211 | |
Gallagher Command Centre | =8.10.1211-maintenance_release5 | |
Gallagher Command Centre | =8.20.1166 | |
Gallagher Command Centre | =8.20.1166-maintenance_release3 | |
Gallagher Command Centre | =8.30.1236 | |
Gallagher Command Centre | =8.30.1236-maintenance_release1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16104 is considered a critical SQL Injection vulnerability that can allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2020-16104, update Gallagher Command Centre to the latest version that addresses this vulnerability.
CVE-2020-16104 affects Gallagher Command Centre versions prior to 8.30.1236 and specific versions between 7.90.0 and 8.20.1166.
An attacker with 'Edit Enterprise Data Interfaces' privilege can execute arbitrary SQL queries against a third-party database.
Yes, CVE-2020-16104 can be exploited remotely if the Enterprise Data Interface is configured to interact with a vulnerable database.