CVE-2021-22851: HGiga OAKloud Portal - SQL injection -1
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22851?
CVE-2021-22851 has been classified as a critical vulnerability due to its potential for SQL injection, allowing attackers to access sensitive database information.
How do I fix CVE-2021-22851?
To fix CVE-2021-22851, update the HGiga OAKlouds OpenID software to a version that is above 2.0-54 or 3.0-54, which patches the SQL injection vulnerability.
What types of attacks can exploit CVE-2021-22851?
CVE-2021-22851 can be exploited by attackers who inject SQL commands into specific URL parameters, compromising the database.
Which versions of HGiga OAKlouds are affected by CVE-2021-22851?
CVE-2021-22851 affects HGiga OAKlouds OpenID versions from 2.0 to 2.0-54 and from 3.0 to 3.0-54.
What are the potential impacts of CVE-2021-22851?
The potential impacts of CVE-2021-22851 include unauthorized access to database schema and sensitive data, leading to data breaches.