SB2026081849 - Integer overflow in BI Connector ODBC Driver
Published: August 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer overflow (CVE-ID: CVE-2026-19001)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in metadata retrieval functions when handling unusually long catalog, schema, or object names. A remote attacker can supply an oversized catalog, schema, or object name to trigger memory corruption and execute arbitrary code.
Successful exploitation may also cause abnormal termination within the calling application's process.
Remediation
Install update from vendor's website.