OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2015-05-26T01:00:00

Updated: 2015-05-26T01:57:00

Reserved: 2015-01-10T00:00:00


Link: CVE-2015-1013

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-05-26T01:59:01.743

Modified: 2015-05-27T16:44:25.970


Link: CVE-2015-1013

JSON object: View

cve-icon Redhat Information

No data.

CWE