Unauthenticated SQL Injection in Seeyon A6 Collaborative Platform
CVE-2015-20122

8.7HIGH

Key Information:

Vendor

Yonyou

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2015-20122?

The Seeyon A6 collaborative office automation platform has a serious vulnerability that allows unauthenticated SQL injection via the attach_ids parameter in the file attachment download endpoint. This issue enables remote attackers to exploit the downloadAtt.jsp endpoint, injecting UNION-based SQL statements to gain access to arbitrary database contents. Sensitive information such as user credentials and system configuration data can be compromised without any prior authentication. The vulnerability was first acknowledged by the Shadowserver Foundation, highlighting the importance of immediate attention and remediation.

Affected Version(s)

A6 OA *

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Shadowserver Foundation
.