NVD disclosure day

Published threat advisories for September 21, 2022

CVE advisoryCRITICAL

CVE-2022-38619

SmartVista SVFE2 SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the SmartVista SVFE2 application, which could allow unauthorized individuals to access or alter sensitive data by manipulating database queries. This issue poses a risk to system integrity and data confidentiality if the vulnerable component is reachable over a network.