CVE-2020-25254: SQL Injection
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. It allows SQL injection, as demonstrated by TestConnectionLocalOrLinkedServer, CreateFilterFriendlyView, or AddWorkViewLinkedServer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25254?
CVE-2020-25254 has a high severity rating due to its potential for SQL injection attacks.
How do I fix CVE-2020-25254?
To fix CVE-2020-25254, update Hyland OnBase to a version above 20.3.10.1000 or the latest available version.
What systems are affected by CVE-2020-25254?
CVE-2020-25254 affects Hyland OnBase versions 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below, and 20.3.10.1000 and below.
Is CVE-2020-25254 exploitable remotely?
Yes, CVE-2020-25254 can be exploited remotely if the affected OnBase systems are accessible over the network.
What kind of attack can CVE-2020-25254 facilitate?
CVE-2020-25254 can facilitate SQL injection attacks, allowing an attacker to manipulate database queries.