CVE-2018-25075
Description
A vulnerability classified as critical has been found in karsany OBridge up to 1.3. Affected is the function getAllStandaloneProcedureAndFunction of the file obridge-main/src/main/java/org/obridge/dao/ProcedureDao.java. The manipulation leads to sql injection. Upgrading to version 1.4 is able to address this issue. The name of the patch is 52eca4ad05f3c292aed3178b2f58977686ffa376. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218376.
References
Permissions RequiredThird Party Advisory
Release NotesThird Party Advisory
Third Party Advisory
PatchThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics