First published: Wed Dec 08 2021(Updated: )
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xylem Aanderaa Geoview | <2.1.3 | |
Xylem, Inc. AADI GeoView Webservice | <2.1.3 | 2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41063 is considered a high-severity SQL injection vulnerability that can allow unauthenticated attackers to execute arbitrary commands.
To fix CVE-2021-41063, upgrade Aanderaa GeoView Webservice to version 2.1.3 or later.
CVE-2021-41063 facilitates SQL injection attacks, which can lead to unauthorized data access and command execution.
Users of Aanderaa GeoView Webservice versions prior to 2.1.3 are affected by CVE-2021-41063.
No, CVE-2021-41063 can be exploited by unauthenticated attackers, making it particularly dangerous.