An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-controlled parameter that is used to create an SQL query. It causes this service to be prone to SQL injection.
https://excellium-services.com/cert-xlm-advisory/CVE-2022-45165/