Vulnerabilidades en ScienceLogic
27 resultadosAnálisis Vexday
A ScienceLogic apresenta um perfil de risco moderado com 27 vulnerabilidades catalogadas, sendo apenas 1 atualmente explorada em ataques ativos e 1 classificada como crítica. A fraqueza dominante é injeção de comandos (CWE-78), um vetor de alto potencial destrutivo. Não há registros de novas vulnerabilidades nos últimos 90 dias, sugerindo que o risco atual é estável e relacionado principalmente a descobertas preexistentes.
CVE-2022-48589HIGHA SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2022-48596HIGHA SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48594HIGHA SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48602HIGHA SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2022-48593HIGHA SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48588HIGHA SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controllEPSS 0.7%CVE-2025-58780HIGHindex.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier becausEPSS 0.2%