CVE-2025-3767
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2025-3767 is a significant SQL Injection vulnerability affecting several versions of Centreon BAM. Malicious users with high privileges can exploit this issue by improperly neutralizing special elements in SQL commands. This vulnerability allows attackers to inject malicious SQL statements, potentially gaining unauthorized access to sensitive data or even taking control of the affected system. It impacts Centreon BAM versions 24.10 before 24.10.1, 24.04 before 24.04.5, 23.10 before 23.10.10, and 23.04 before 23.04.10. Users are advised to update their Centreon BAM installations as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Banker's Toolox BAM+
- Centreon BAM
Affected Vendors
- Abrigo
- Centreon