Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Fixes

Solution

Upgrade to versions 4.7.2, 4.6.11 or higher


Workaround

No workaround given by the vendor.

History

Fri, 16 May 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Peak-14
Peak-14 cavok
CPEs cpe:2.3:a:peak-14:cavok:*:*:*:*:*:*:*:*
Vendors & Products Peak-14
Peak-14 cavok

Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Cavok
Cavok cavok
CPEs cpe:2.3:a:cavok:cavok:*:*:*:*:*:*:*:*
Vendors & Products Cavok
Cavok cavok
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 06 Oct 2024 12:30:00 +0000

Type Values Removed Values Added
Description Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Title Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2024-10-07T15:07:47.911Z

Reserved: 2024-08-25T06:16:04.248Z

Link: CVE-2024-45249

cve-icon Vulnrichment

Updated: 2024-10-07T15:07:39.979Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-06T13:15:15.313

Modified: 2025-05-16T17:09:45.523

Link: CVE-2024-45249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.