Code Injection in SQLite JDBC Driver - CVE-2023-32697

 

Code Injection in SQLite JDBC Driver - CVE-2023-32697

Published: August 15, 2023


Vulnerability identifier: #VU79519
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32697
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

SQLite JDBC Driver
IBM Process Mining
QRadar User Behavior Analytics
IBM Maximo Asset Management
IBM Maximo Application Suite
EMC Data Protection Advisor
IBM Data Risk Manager
Oracle SOA Suite
IBM Qradar SIEM
openEuler
sqlite-jdbc
sqlite-jdbc-javadoc
IBM Security Verify Access

How to mitigate CVE-2023-32697

Install updates from vendor's website.

SQLite JDBC Driver - update to 3.41.2.2
IBM Process Mining - update to 1.14.2
IBM Data Risk Manager - update to 2.0.6.18
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
sqlite-jdbc - update to 3.15.1-2
sqlite-jdbc-javadoc - update to 3.15.1-2
QRadar User Behavior Analytics - update to 4.1.13
IBM Maximo Asset Management - addressed in versions 7.6.1.2.36, 7.6.1.3.11
IBM Maximo Application Suite - addressed in versions 8.9.9, 8.10.4
IBM Security Verify Access - update to 10.0.7.0
EMC Data Protection Advisor - addressed in versions 19.8 71, 19.9 67

External References

Related Security Bulletins