PatchSiren cyber security CVE debrief
CVE-2022-2504 SDD Computer Software CVE debrief
A critical SQL injection vulnerability exists in SDD-Baro, a software product by SDD Computer Software. The flaw stems from improper neutralization of special elements in SQL commands (CWE-89), allowing unauthenticated attackers to execute arbitrary SQL statements. The vulnerability affects all versions prior to 2.8.432. The issue was disclosed by the Turkish National Cyber Security Incident Response Team (USOM) in advisory TR-23-0107. Organizations using affected versions should upgrade to SDD-Baro 2.8.432 or later immediately, as this vulnerability is remotely exploitable without authentication and carries the highest severity rating.
- Vendor
- SDD Computer Software
- Product
- SDD-Baro
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-02-23
- Original CVE updated
- 2026-05-20
- Advisory published
- 2023-02-23
- Advisory updated
- 2026-05-20
Who should care
Organizations running SDD-Baro for business operations, particularly those with internet-exposed instances or containing sensitive business/financial data. Database administrators and application security teams responsible for legacy .NET or Windows-based business applications should prioritize this patch.
Technical summary
SDD-Baro versions prior to 2.8.432 contain an SQL injection vulnerability due to improper input sanitization. The flaw allows network-based attackers without credentials to inject malicious SQL commands, potentially leading to complete database compromise, data exfiltration, authentication bypass, and server-side code execution. The CVSS 3.1 score of 9.8 reflects network attack vector, low complexity, no privileges required, no user interaction, and high impact across confidentiality, integrity, and availability. The vulnerability was reported through coordinated disclosure via USOM (Turkish National Cyber Security Incident Response Team) in February 2023.
Defensive priority
critical
Recommended defensive actions
- Upgrade SDD-Baro to version 2.8.432 or later immediately.
- If immediate patching is not possible, restrict network access to SDD-Baro administrative interfaces to trusted IP ranges only.
- Monitor database query logs for anomalous SQL syntax or unexpected table access patterns.
- Review application logs for suspicious authentication attempts or unusual data retrieval patterns.
- Conduct code review of any custom SQL query implementations in SDD-Baro deployments for additional injection vectors.
Evidence notes
CVE published 2023-02-23; modified 2026-05-20. Advisory TR-23-0107 published by USOM (Turkish National Cyber Security Incident Response Team). CPE confirms affected versions: sdd-baro_project:sdd-baro versions before 2.8.432. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Official resources
-
CVE-2022-2504 CVE record
CVE.org
-
CVE-2022-2504 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
2023-02-23