PT-2026-97684 · Unknown · Java110 Microcommunity
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
java110 MicroCommunity versions prior to 2.1
Description
Remote manipulation of the
fallBackSql argument within the QueryServiceSMOImpl.fallBack() function of the BusinessApi.java file in the fallBack API endpoint allows for SQL injection. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the fallBack API endpoint or avoid using the
fallBackSql parameter until a patch is available.Exploit
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java110 Microcommunity