Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
References
Link | Resource |
---|---|
https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC | Issue Tracking Vendor Advisory |
https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC - Issue Tracking, Vendor Advisory |
18 Aug 2023, 14:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-89 | |
First Time |
Microsoft
Snowsoftware snow License Manager Snowsoftware Microsoft windows |
|
References | (MISC) https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC - Issue Tracking, Vendor Advisory | |
CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:service_provider:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
11 Aug 2023, 12:58
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-11 12:15
Updated : 2024-11-21 08:18
NVD link : CVE-2023-3864
Mitre link : CVE-2023-3864
CVE.ORG link : CVE-2023-3864
JSON object : View
Products Affected
snowsoftware
- snow_license_manager
microsoft
- windows
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')