SQL injection in Financial Transaction Manager for Digital Payments (DP) - CVE-2019-4575

 

SQL injection in Financial Transaction Manager for Digital Payments (DP) - CVE-2019-4575

Published: June 15, 2022


Vulnerability identifier: #VU64383
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4575
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send specially-crafted SQL statements to perform a denial of service attack.


Affected software

Financial Transaction Manager for Digital Payments (DP)
Financial Transaction Manager for Corporate Payment Services (CPS)
Financial Transaction Manager for High Value Payments

How to mitigate CVE-2019-4575

Install updates from vendor's website.

Financial Transaction Manager for Digital Payments (DP) - update to 3.2.10
Financial Transaction Manager for Corporate Payment Services (CPS) - update to 3.2.10
Financial Transaction Manager for High Value Payments - update to 3.2.11

External References

Related Security Bulletins