Overview
Misys FusionCapital Opics Plus is used by regional and local financial institutions to manage treasuries. FusionCapital Opics Plus contains several vulnerabilities.
Description
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - CVE-2016-5653 According to the reporter, an authenticated but low privileged user may exploit a SQL Injection in the "ID" and "Branch" parameters of a search and enumerate the full database. |
Impact
An authenticated attacker may be able escalate privileges to administrator, or perform full searches on the database. An unauthenticated attacker may be able decrypt SSL traffic between the client and server. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem. |
Restrict Network Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 8.5 | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Temporal | 7.7 | E:POC/RL:U/RC:C |
Environmental | 2.2 | CDP:H/TD:L/CR:H/IR:H/AR:H |
References
Acknowledgements
Thanks to Wissam Bashour for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2016-5653, CVE-2016-5654, CVE-2016-5655 |
Date Public: | 2016-07-19 |
Date First Published: | 2016-07-19 |
Date Last Updated: | 2016-08-08 14:22 UTC |
Document Revision: | 46 |