Executive brief
A critical security vulnerability has been identified in Rolantis Agentis, a software platform used for information technology management. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive customer data, modify records, or disrupt business operations. This issue is particularly severe because it can be exploited remotely without any valid user credentials.
Technical details
A SQL injection vulnerability (CWE-89) exists in Rolantis Information Technologies Agentis due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. Given the CVSS score of 10.0 and the 'Scope: Changed' (S:C) metric, an exploit could lead to full compromise of the database and potentially the underlying host. The vulnerability is resolved in Agentis version 4.32.
Affected products
- Rolantis Information Technologies Agentis before 4.32
Timeline
- 2025-07-22: advisory: Initial advisory published by TR-CERT (USOM)
- 2025-07-22: disclosed