CVE-2018-16803
Description
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CIMTechniques CIMScan 6.x through 6.2 SOAP WSDL parser allows unauthenticated SQL code execution, risking full compromise of the affected system.
Vulnerability
CIMTechniques CIMScan versions 6.x through 6.2 contain a critical vulnerability in the SOAP WSDL parser component. The parser fails to properly sanitize input, allowing an attacker to inject and execute arbitrary SQL code [1]. This affects the core scanning functionality that processes WSDL definitions.
Exploitation
An attacker can exploit this vulnerability remotely over the network without any authentication or user interaction. The SOAP WSDL parser is exposed in the application's default configuration. By sending a crafted SOAP request containing malicious SQL payloads in the WSDL data, the attacker triggers the SQL injection within the parser's database operations [1].
Impact
Successful exploitation leads to arbitrary SQL code execution within the context of the CIMScan application's database user. The attacker can read, modify, or delete database contents, potentially gaining complete control over the underlying information system. The Department of Defense assessed this as a critical severity issue (CVSS 9–10) [1]. Full compromise of the website and its hosted data is possible.
Mitigation
The vendor rapidly mitigated the vulnerability after disclosure to the DoD Vulnerability Disclosure Program [1]. However, the specific patched version is not disclosed in the available references. Users are advised to contact CIMTechniques for patch availability and to apply any security updates immediately. No workaround information is provided. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: >=6.0, <=6.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- twitter.com/DC3VDP/status/1083359509995753473mitrex_refsource_MISC
- www.linkedin.com/feed/update/urn:li:activity:6489145511902212096/mitrex_refsource_MISC
- www.websec.nl/news.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.