A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in data corruption.
The product’s user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Database_manager | Bd | 3.0.1.0 (including) | 3.0.1.0 (including) |
Performa | Bd | * | 3.0.0.0 (including) |
Reada | Bd | * | 1.1.0.2 (including) |