Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Siemens COMOS 未明安全绕过漏洞
Vulnerability Description
Siemens COMOS是集成生命周期工程领域内全球领先的软件解决方案供应商。 Siemens COMOS中存在漏洞,可被恶意攻击者利用绕过某些安全限制。该漏洞源于与‘published’方法相关的未明错误。攻击者可利用该漏洞获取对数据库的管理访问权限。成功的利用需要有数据库的读取访问权限。早期版本至9.1 Patch 413版本、9.2 Update 03 Patch 023、10.0 Patch 005、10.0 SP1版本中存在漏洞。
CVSS Information
N/A
Vulnerability Type
N/A