Impact
Evergreen version releases up to 3.14.11, 3.15.11, 3.16.5 and 3.17-beta1 contain an undisclosed function in the open-ils.fielder OpenSRF Service that accepts unsanitized input and allows a crafted input to inject arbitrary SQL commands. This flaw can be leveraged to read, modify, delete, or possibly execute database commands, thereby compromising the confidentiality, integrity, or availability of the database contents and, depending on the database configuration, could lead to remote code execution. The vulnerability is classified as an SQL injection (CWE‑89) and is accessible through the /osrf-gateway-v1 endpoint.
Affected Systems
All Evergreen installations running 3.14.11 or older, 3.15.11 or older, 3.16.5 or older, and 3.17-beta1 or older are affected. The vendor has released patch versions 3.14.12, 3.15.12, 3.16.6 and 3.17-beta2 that fix the injection issue; updating to at least these versions is required to remediate.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. No EPSS score is reported, but the flaw has been publicly disclosed and the exploit is known to be usable remotely, which increases practical risk. Because the compromised interface is reachable over the network, an attacker can reach it from remote systems. The vulnerability is not listed in the CISA KEV catalog, but its remote nature and potential for data loss or code compromise make rapid mitigation critical.
OpenCVE Enrichment