In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
2022-02-24T15:15:29.350
2024-11-21T06:50:21.343
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cyrusimap | cyrus-sasl | ≤ 2.1.27 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | ontap_select_deploy_administration_utility | - | Yes |
Application | oracle | communications_cloud_native_core_console | 22.2.0 | Yes |
Application | oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.2.0 | Yes |
Application | oracle | communications_cloud_native_core_security_edge_protection_proxy | 22.1.1 | Yes |