CVE-2026-42100
Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.68%
- CWE
- CWE-228
- Published
- 2026-05-19
- Last modified
- 2026-05-19
Affected products
- Sparx Systems Pro Cloud Server
Weakness type
Related vulnerabilities
- CVE-2026-50103 — Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
- CVE-2025-59174 — Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an...
- CVE-2026-25657 — Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-34232 — Firebird: DoS via `op_response` packet from client
- CVE-2024-53828 — Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-20125 — A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release...
- CVE-2025-2529 — IBM Terracotta denial of service
- CVE-2025-47736 — dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash...