CVE-2021-37197

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:comos:10.4:*:*:*:*:*:*:*

History

21 Nov 2024, 06:14

Type Values Removed Values Added
References () https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf - Patch, Vendor Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf - Patch, Vendor Advisory

30 Apr 2022, 02:26

Type Values Removed Values Added
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.0
v3 : 8.8
CPE cpe:2.3:a:siemens:comos:10.4:*:*:*:*:*:*:*

12 Apr 2022, 09:15

Type Values Removed Values Added
Summary A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.2.14 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements. A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.

09 Feb 2022, 16:15

Type Values Removed Values Added
Summary A vulnerability has been identified in COMOS (All versions < V10.4.1). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements. A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.2.14 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.

14 Jan 2022, 02:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CWE CWE-89
CPE cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
References (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf - (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf - Patch, Vendor Advisory

11 Jan 2022, 12:45

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-11 12:15

Updated : 2024-11-21 06:14


NVD link : CVE-2021-37197

Mitre link : CVE-2021-37197

CVE.ORG link : CVE-2021-37197


JSON object : View

Products Affected

siemens

  • comos
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')