First published: Thu Sep 05 2024(Updated: )
SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto SafeNet CDG | <=5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42885 is classified as a critical SQL injection vulnerability that allows attackers to execute arbitrary code.
To fix CVE-2024-42885, upgrade ESAFENET CDG to a version later than 5.6 to mitigate the SQL injection risk.
CVE-2024-42885 affects ESAFENET CDG version 5.6 and all earlier versions.
Yes, CVE-2024-42885 can potentially lead to data loss by allowing an attacker to execute arbitrary SQL commands and manipulate the database.
The attack vector for CVE-2024-42885 is through the id parameter of the data.jsp page, which is vulnerable to SQL injection.