ZeroHour

CVE-2022-24407

CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
Modified
Description

In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

Vendors
cyrusimapdebianfedoraprojectnetapporacle
Products
cyrus-sasl, debian linux, fedora, active iq unified manager, ontap select deploy administration utility, communications cloud native core console, communications cloud native core network function cloud native environment, communications cloud native core security edge protection proxy
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.