CVE-2022-24407
—CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
- Vendors
- cyrusimapdebianfedoraprojectnetapporacle
- Products
- cyrus-sasl, debian linux, fedora, active iq unified manager, ontap select deploy administration utility, communications cloud native core console, communications cloud native core network function cloud native environment, communications cloud native core security edge protection proxy
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.