Security Advisory

CVE-2021-38481

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-10-22 11:22:32
Last updated 2024-09-16 22:46:06
Assigner icscert
State PUBLISHED

Description

The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of the supplied JOB ID provided to the function. An attacker may send a malicious payload that can enable the user to execute another SQL expression by sending a specific string.