CVE-2015-5049
MEDIUMIBM Openpages Grc Platform - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in the API in IBM OpenPages GRC Platform 7.0 before 7.0.0.4 IF3 and 7.1 before 7.1.0.1 IF6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Scores
CVSS v3
5.4
EPSS
0.0013
EPSS Percentile
31.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-89
Status
draft
Affected Products (7)
ibm/openpages_grc_platform
ibm/openpages_grc_platform
ibm/openpages_grc_platform
ibm/openpages_grc_platform
ibm/openpages_grc_platform
ibm/openpages_grc_platform
ibm/openpages_grc_platform
Timeline
Published
Jan 01, 2016
Tracked Since
Feb 18, 2026