CVE-2020-35122: SQL Injection
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35122?
CVE-2020-35122 has a high severity rating due to the potential for SQL injection attacks.
How can I fix CVE-2020-35122?
To fix CVE-2020-35122, upgrade the Keysight Database Connector plugin to version 1.5.0 or later.
What are the consequences of exploiting CVE-2020-35122?
Exploiting CVE-2020-35122 allows a malicious user to execute arbitrary SQL commands on the database.
Who is affected by CVE-2020-35122?
Any users of the Keysight Database Connector plugin for Confluence version prior to 1.5.0 are affected by CVE-2020-35122.
What is the nature of the vulnerability in CVE-2020-35122?
CVE-2020-35122 is a vulnerability that allows bypassing access controls for saved database connection profiles.