7.5
CVE-2026-42100
- EPSS 0.68%
- Veröffentlicht 19.05.2026 12:59:50
- Zuletzt bearbeitet 02.06.2026 14:19:20
- Quelle cvd@cert.pl
- CVE-Watchlists
- Unerledigt
DoS in Sparx Pro Cloud Server
Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sparxsystems ≫ Pro Cloud Server Version <= 6.1.167
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.68% | 0.476 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| cvd@cert.pl | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-228 Improper Handling of Syntactically Invalid Structure
The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.
https://cert.pl/en/posts/2026/05/CVE-2026-42096
https://sparxsystems.com/products/procloudserver/
https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html
https://efigo.pl/blog/CVE-2026-42096/