CVE-2023-45162

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
13/10/2023
Last modified:
20/05/2025

Description

Affected 1E Platform versions have a Blind SQL Injection vulnerability that can lead to arbitrary code execution. <br /> <br /> Application of the relevant hotfix remediates this issue.<br /> <br /> for v8.1.2 apply hotfix Q23166<br /> for v8.4.1 apply hotfix Q23164<br /> for v9.0.1 apply hotfix Q23169<br /> <br /> SaaS implementations on v23.7.1 will automatically have hotfix Q23173 applied. Customers with SaaS versions below this are urged to upgrade urgently - please contact 1E to arrange this

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1e:platform:8.1.2:*:*:*:*:*:*:*
cpe:2.3:a:1e:platform:8.4.1:*:*:*:*:*:*:*
cpe:2.3:a:1e:platform:9.0.1:*:*:*:*:*:*:*
cpe:2.3:a:1e:platform:23.7.1:*:*:*:*:*:*:*