CVE-2024-52057

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.*, from 5.2.0 before 5.3.*.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*

History

02 Oct 2025, 13:34

Type Values Removed Values Added
References () https://www.rti.com/vulnerabilities/#cve-2024-52057 - () https://www.rti.com/vulnerabilities/#cve-2024-52057 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en RTI Connext Professional (Servicio de cola) permite la inyección SQL. Este problema afecta a Connext Professional: desde 7.0.0 antes de 7.3.0, desde 6.1.0 antes de 6.1.2.17, desde 6.0.0 antes de 6.0.*, desde 5.2.0 antes de 5.3.*.
First Time Rti connext Professional
Rti
CPE cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*

13 Dec 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-13 10:15

Updated : 2025-10-02 13:34


NVD link : CVE-2024-52057

Mitre link : CVE-2024-52057

CVE.ORG link : CVE-2024-52057


JSON object : View

Products Affected

rti

  • connext_professional
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')