CVE-2023-45162
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
13/10/2023
Last modified:
20/05/2025
Description
Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution. <br />
<br />
Application of the relevant hotfix remediates this issue.<br />
<br />
for v8.1.2 apply hotfix Q23166<br />
for v8.4.1 apply hotfix Q23164<br />
for v9.0.1 apply hotfix Q23169<br />
<br />
SaaS implementations on v23.7.1 will automatically have hotfix Q23173 applied. Customers with SaaS versions below this are urged to upgrade urgently - please contact 1E to arrange this
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:1e:platform:8.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:1e:platform:8.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:1e:platform:9.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:1e:platform:23.7.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



