First published: Wed Jul 20 2022(Updated: )
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Digiwin Business Process Management | <5.8.8.1 |
Update version to 5.8.8.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32456 is rated as high severity due to its potential for unauthorized database access and manipulation.
To fix CVE-2022-32456, upgrade Digiwin Business Process Management to version 5.8.8.1 or later.
Organizations using Digiwin Business Process Management versions before 5.8.8.1 are at risk from CVE-2022-32456.
CVE-2022-32456 allows unauthenticated remote attackers to perform SQL injection attacks.
CVE-2022-32456 can lead to database access, modification, deletion, or even service disruption.