CVE-2025-3767

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 89

Summary

CVE-2025-3767 is a significant SQL Injection vulnerability affecting several versions of Centreon BAM. Malicious users with high privileges can exploit this issue by improperly neutralizing special elements in SQL commands. This vulnerability allows attackers to inject malicious SQL statements, potentially gaining unauthorized access to sensitive data or even taking control of the affected system. It impacts Centreon BAM versions 24.10 before 24.10.1, 24.04 before 24.04.5, 23.10 before 23.10.10, and 23.04 before 23.04.10. Users are advised to update their Centreon BAM installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Banker's Toolox BAM+
  • Centreon BAM

Affected Vendors

  • Abrigo
  • Centreon