CVE-2024-57640
Published: 14 January 2025
Description
An issue in the dc_add_int component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Security Summary
CVE-2024-57640 is a vulnerability in the dc_add_int component of OpenLink Virtuoso OpenSource version 7.2.11. The issue allows attackers to cause a Denial of Service (DoS) condition through crafted SQL statements. It has been assigned a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) and is associated with CWE-89 (Improper Neutralization of Special Elements used in an SQL Command, or SQL Injection).
The vulnerability can be exploited by unauthenticated remote attackers over the network with low complexity and no user interaction required. Successful exploitation enables high-impact integrity violations, as indicated by the CVSS metrics, potentially allowing manipulation of data integrity without affecting confidentiality or availability directly.
Mitigation details are referenced in the GitHub issue at https://github.com/openlink/virtuoso-opensource/issues/1184, which provides additional context on the vulnerability.
Details
- CWE(s)