CVE Vulnerabilities

CVE-2018-10593

Product UI does not Warn User of Unsafe Actions

Published: May 24, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H
CVSS 2.x
3.8 LOW
AV:A/AC:M/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in data corruption.

Weakness

The product’s user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.

Affected Software

Name Vendor Start Version End Version
Database_manager Bd 3.0.1.0 (including) 3.0.1.0 (including)
Performa Bd * 3.0.0.0 (including)
Reada Bd * 1.1.0.2 (including)

References