CVE-2020-16165: SQL Injection
Published Jul 30, 2020
·Updated
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
Affected Software
2 affected components
Springblade Project Springblade<=2.7.1
Bladex Springblade<=2.7.1
Event History
Jul 30, 2020
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-16165?
CVE-2020-16165 is a vulnerability in the DAO/DTO implementation in SpringBlade through 2.7.1 that allows SQL Injection in an ORDER BY clause.
2
How severe is CVE-2020-16165?
CVE-2020-16165 has a severity level of critical, with a CVSS score of 9.8.
3
What software versions are affected by CVE-2020-16165?
CVE-2020-16165 affects SpringBlade versions up to and including 2.7.1.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2020-16165?
The CWE associated with CVE-2020-16165 is CWE-89 (SQL Injection).
5
How can I mitigate CVE-2020-16165?
To mitigate CVE-2020-16165, it is recommended to update to a version of SpringBlade that is higher than 2.7.1 or apply a patch provided by the vendor.