SQL injection in Financial Transaction Manager for Digital Payments (DP) - CVE-2019-4575
Published: June 15, 2022
Vulnerability identifier: #VU64383
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4575
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send specially-crafted SQL statements to perform a denial of service attack.
Affected software
Financial Transaction Manager for Digital Payments (DP)
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for High Value Payments
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for High Value Payments
How to mitigate CVE-2019-4575
Install updates from vendor's website.
Financial Transaction Manager for Digital Payments (DP) - update to 3.2.10
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.10
Financial Transaction Manager for High Value Payments - update to 3.2.11
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.10
Financial Transaction Manager for High Value Payments - update to 3.2.11