MEDIUM · 6.5

CVE-2015-1013

OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended comma...

Vulnerability Description

OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.

CVSS Score

6.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OsisoftPi Server2.6
OsisoftPi Sql For Af2.1.2.19

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-1013?

CVE-2015-1013 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended comma...

How severe is CVE-2015-1013?

CVE-2015-1013 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-1013?

Check the references section above for vendor advisories and patch information. Affected products include: Osisoft Pi Server, Osisoft Pi Sql For Af.