CVE-2021-30055: SQL Injection
Published Apr 5, 2021
·Updated
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'paryear' parameter when running a report.
Affected Software
1 affected component
eng Knowage<7.4
Event History
Apr 5, 2021
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-30055?
CVE-2021-30055 has been classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2021-30055?
To fix CVE-2021-30055, it's recommended to upgrade Knowage Suite to version 7.4 or later.
3
Where does CVE-2021-30055 occur in Knowage Suite?
CVE-2021-30055 occurs in the documentexecution/url analytics driver component via the 'par_year' parameter.
4
What are the potential impacts of exploiting CVE-2021-30055?
Exploiting CVE-2021-30055 could allow an attacker to execute arbitrary SQL commands on the database.
5
Is there a workaround for CVE-2021-30055 if I cannot upgrade?
No specific workaround is mentioned for CVE-2021-30055, so upgrading is the safest option.