SB2017062226 - SQL injection in SQL Monitor



SB2017062226 - SQL injection in SQL Monitor

Published: June 22, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017062226
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) SQL injection (CVE-ID: CVE-2015-9098)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines. If the Base Monitor is connecting to these machines using an account with SQL admin privileges, then code execution on the operating system can result in full system compromise (if Microsoft SQL Server is running with local administrator privileges).


Remediation

Install update from vendor's website.