SQL injection in Ree6 - CVE-2022-39303
Published: February 28, 2024
Vulnerability identifier: #VU86887
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39303
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Affected software
Ree6
IBM Watson Machine Learning Accelerator
IBM Watson Machine Learning Accelerator
How to mitigate CVE-2022-39303
Install update from vendor's website.
Ree6 - update to 1.7.0
IBM Watson Machine Learning Accelerator - update to 3.0.0
IBM Watson Machine Learning Accelerator - update to 3.0.0