CVE-2015-1013

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
26/05/2015
Last modified:
12/04/2025

Description

OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:osisoft:pi_server:2.6:*:*:*:*:*:*:*
cpe:2.3:a:osisoft:pi_sql_for_af:2.1.2.19:*:*:*:*:*:*:*