Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.*, from 5.2.0 before 5.3.*.
The vulnerability results from improper neutralization of special characters in SQL queries in the Queuing Service component. A remote unauthenticated attacker can inject malicious SQL commands into queries directed to the database. This requires certain technical conditions to be met on the environment side (AT:P in the CVSS vector), but does not require any user interaction.
A successful attack allows unauthorized reading and modification of data stored in the RTI Connext Professional system database. This can lead to disclosure of sensitive information and compromise of data integrity processed by the system.
RTI Connext Professional should be updated to version 7.3.0 or newer (for the 7.x branch) or to version 6.1.2.17 or newer (for the 6.1.x branch). Users of the 6.0.x and 5.2.x branches should consult with the vendor and apply patches available according to references at https://www.rti.com/vulnerabilities/#cve-2024-52057. It is recommended to limit network access to the Queuing Service only to trusted hosts as a temporary measure.
RTI Connext Professional in versions: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.* (all versions of the 6.0.x branch), from 5.2.0 before 5.3.* (all versions of the 5.2.x branch).
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRti Connext Professional
APPRti5.2.0 – 6.1.2.17 (excl.)7.0.0 – 7.3.0 (excl.)
Related vulnerabilities
Out-of-bounds Read w RTI Connext Professional — przeciążenie dostępności
Heap-based Buffer Overflow w RTI Connext Professional (Core Libraries)
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Profession...
Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) a...
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Servi...