CVE-2020-4902: SQL Injection
IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191045.
Other sources
IBM Datacap Taskmaster Capture is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4902?
The severity of CVE-2020-4902 is considered high due to its potential for remote SQL injection attacks.
How do I fix CVE-2020-4902?
To fix CVE-2020-4902, update IBM Datacap Navigator to version 9.1.8 or later where the vulnerability is resolved.
What systems are affected by CVE-2020-4902?
CVE-2020-4902 affects IBM Datacap Navigator version 9.1.7 running on Microsoft Windows.
What type of vulnerability is CVE-2020-4902?
CVE-2020-4902 is a SQL injection vulnerability that allows attackers to manipulate database operations.
Can CVE-2020-4902 lead to data compromise?
Yes, CVE-2020-4902 can allow attackers to view, add, modify, or delete data in the back-end database.