Vulnerabilities > CVE-2021-44498 - NULL Pointer Dereference vulnerability in Fisglobal Gt.M

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
fisglobal
CWE-476

Summary

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

Vulnerable Configurations

Part Description Count
Application
Fisglobal
1

Common Weakness Enumeration (CWE)