SQL Injection Vulnerability in eDNA Enterprise Data Historian by eDNA
CVE-2020-13499
9.8CRITICAL
What is CVE-2020-13499?
An SQL injection vulnerability exists in the CHaD.asmx web service of eDNA Enterprise Data Historian that can be exploited through specially designed SOAP requests. Attackers can leverage this flaw by manipulating the InstancePath parameter, allowing them to execute unauthorized SQL commands that may lead to a potential data compromise. This vulnerability poses a significant risk for organizations using these affected versions of the product.
Affected Version(s)
Aveva Aveva eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053