CVE-2021-37197

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:comos:10.4:*:*:*:*:*:*:*

History

30 Apr 2022, 02:26

Type Values Removed Values Added
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.0
v3 : 8.8
CPE cpe:2.3:a:siemens:comos:10.4:*:*:*:*:*:*:*

12 Apr 2022, 09:15

Type Values Removed Values Added
Summary A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.2.14 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements. A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.

09 Feb 2022, 16:15

Type Values Removed Values Added
Summary A vulnerability has been identified in COMOS (All versions < V10.4.1). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements. A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.2.14 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is vulnerable to SQL injections. This could allow an attacker to execute arbitrary SQL statements.

14 Jan 2022, 02:56

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
First Time Siemens comos
Siemens
CPE cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
References (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf - (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-995338.pdf - Patch, Vendor Advisory
CWE CWE-89

11 Jan 2022, 12:45

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-11 12:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-37197

Mitre link : CVE-2021-37197

CVE.ORG link : CVE-2021-37197


JSON object : View

Products Affected

siemens

  • comos
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')