CVE-2021-41063: SQL Injection
Published Dec 8, 2021
·Updated
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.
Affected Software
2 affected componentsFixes available
Xylem Aanderaa Geoview<2.1.3
Xylem, Inc. AADI GeoView Webservice<2.1.3
2.1.3
Event History
Dec 8, 2021
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
Description
Aug 4, 2024
Data Sourced
via ICS·03:05 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-41063?
CVE-2021-41063 is considered a high-severity SQL injection vulnerability that can allow unauthenticated attackers to execute arbitrary commands.
2
How do I fix CVE-2021-41063?
To fix CVE-2021-41063, upgrade Aanderaa GeoView Webservice to version 2.1.3 or later.
3
What type of attack does CVE-2021-41063 facilitate?
CVE-2021-41063 facilitates SQL injection attacks, which can lead to unauthorized data access and command execution.
4
Who is affected by CVE-2021-41063?
Users of Aanderaa GeoView Webservice versions prior to 2.1.3 are affected by CVE-2021-41063.
5
Is authentication required to exploit CVE-2021-41063?
No, CVE-2021-41063 can be exploited by unauthenticated attackers, making it particularly dangerous.