External risk intelligence

SQL Injection in OASYS SYSOA Allows Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-67066

The vulnerability exists in a web application path (/outaddresspaging) reachable via an HTTP parameter, which is a common deployment pattern for web-based services. Because it is a web application accessible over the network, it is commonly exposed as an internet-facing endpoint.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical SQL injection vulnerability has been identified in oasys sysoa version 1.0, potentially allowing remote attackers to execute arbitrary code. This issue, stemming from the way the system handles certain input parameters, could pose a significant risk if left unaddressed. Understanding the nature of this vulnerability is key to assessing our exposure and ensuring our systems remain secure.

  • Attackers can run unauthorized code remotely.
  • Matters due to its remote and unauthenticated exploitation.
  • Confirm relevance and potential impact to our environment.

Attack Path

How an attacker could exploit the issue

An attacker could target a web application accessible over the internet, specifically the `/outaddresspaging` path. By manipulating the `outtype` parameter, they could trigger a SQL injection vulnerability, potentially leading to the execution of arbitrary code on the system.

  • No authentication required.
  • Inject malicious SQL via `outtype` parameter.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the affected system by manipulating the 'outtype' parameter within the '/outaddresspaging' path. This could lead to unauthorized modification or disclosure of system data, depending on the privileges of the database user.

  • Arbitrary code execution on the system.
  • Exploited via network requests to a specific path.
  • Potential for unauthorized system access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Security and infrastructure teams are likely responsible for addressing this SQL injection vulnerability. The first practical step is to identify all instances of oasys sysoa, determine their network exposure, and confirm their business criticality. This will allow for risk-based prioritization and planning for remediation.

  • Identify affected systems and owners.
  • Verify network reachability and business impact.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is oasys sysoa?

Oasys SYSOA is a software application designed to handle structured data processes. Version 1.0 specifically includes web-based features that interact with back-end databases to manage information flow, such as handling paging requests for address data, which makes it a functional component in environments that prioritize data retrieval and system organization.

What does CVE-2025-67066 mean by SQL injection?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain English, the software fails to properly filter user input. This allows an attacker to insert their own database commands into the system's queries, potentially tricking the application into running unauthorized instructions instead of just retrieving data.

How can an attacker trigger this vulnerability?

An attacker targets the /outaddresspaging path and manipulates the 'outtype' parameter to inject malicious code. It is important to note that this bug is not triggered by standard usage or legitimate navigation of the software; it requires a deliberate, specially crafted network request designed to bypass the application's intended input handling.

Is my system at risk if it runs oasys sysoa?

Halo Surface Signal indicates this vulnerability is likely reachable because the affected path is a common web application endpoint. If your instance of oasys sysoa is accessible from the internet, the risk increases significantly because remote, unauthenticated attackers can attempt to trigger the vulnerability without needing prior system access.

Do I need to act immediately on this vulnerability?

You should begin by locating all deployments of oasys sysoa version 1.0 within your environment. Once identified, evaluate whether these systems are exposed to the network and determine their role in your operations. This assessment helps you prioritize which systems require the most urgent attention and planning for a security update.

References