A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.
References
Link | Resource |
---|---|
https://www.bd.com/en-us/support/product-security-and-privacy/product-security-bulletin-bd-kiestra-tla-bd-kiestra-wca-bd-inoqula | Vendor Advisory |
https://ics-cert.us-cert.gov/advisories/ICSMA-18-142-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-05-24 09:29
Updated : 2019-10-09 16:32
NVD link : CVE-2018-10595
Mitre link : CVE-2018-10595
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
bd
- reada
- kiestra_tla
- performa
- inoqula\+
- kiestra_wca
- database_manager