CVE-2024-12746

A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0.
Configurations

No configuration.

History

26 Dec 2024, 15:15

Type Values Removed Values Added
References
  • () https://aws.amazon.com/security/security-bulletins/AWS-2024-015/ -

24 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-24 17:15

Updated : 2024-12-26 15:15


NVD link : CVE-2024-12746

Mitre link : CVE-2024-12746

CVE.ORG link : CVE-2024-12746


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')