SQL injection in Postgresql JDBC Driver - CVE-2024-1597
Published: March 4, 2024 / Updated: March 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data when using the "PreferQueryMode=SIMPLE" option. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Affected software
Cloud Pak for Security (CP4S)
Jira Software Server
IBM Qradar SIEM
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Server Applications Module
openSUSE Leap
openEuler
Fedora
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Security Verify Information Queue
PowerStore T
Security QRadar EDR
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
InfoSphere Data Replication
QRadar Suite
Red Hat build of Quarkus
Confluence Data Center
IBM Tivoli Netcool Impact
Bamboo Server
Jira Software Data Center
Oracle Enterprise Data Quality
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite
IBM Security Verify Governance
IBM Observability with Instana
Openfire
Rundeck
Confluence Server
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
postgresql-jdbc
postgresql-jdbc (Red Hat package)
postgresql-jdbc-javadoc
postgresql-jdbc-help
Bosh Release for the UAA
Red Hat OpenShift Serverless
IBM Disconnected Log Collector
IBM Storage Scale System
How to mitigate CVE-2024-1597
QRadar Suite - update to 1.10.20.0
Red Hat build of Quarkus - addressed in versions 2.13.9.SP2, 3.2.11
Openfire - update to 4.8.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Rundeck - addressed in versions 4.17.5, 5.1.1
Confluence Data Center - addressed in versions 7.19.21, 8.5.8, 8.9.0
Confluence Server - addressed in versions 7.19.21, 8.5.8, 8.9.0
IBM Tivoli Netcool Impact - update to 7.1.0.33
Red Hat Single Sign-On - update to 7.6.7
Bamboo Server - addressed in versions 9.2.12, 9.4.4, 9.5.2
Jira Software Data Center - addressed in versions 9.4.19, 9.12.6, 9.15.2
Jira Software Server - addressed in versions 9.4.19, 9.12.6, 9.15.2
IBM Security Verify Information Queue - update to 10.0.8
Bosh Release for the UAA - update to 74.5.105
Netcool Operations Insight - update to 1.6.12
IBM Disconnected Log Collector - update to 1.8.5
Red Hat OpenShift Serverless - update to 1.33.0
PowerStore T - update to 3.6.1.2-2315284
Security QRadar EDR - update to 3.12.8
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
IBM Cloud Pak for Watson AIOps - update to 4.5.0
DB2 on Cloud Pak for Data - update to 4.8.5
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Storage Scale System - addressed in versions 5.1.9.3, 5.2.0.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Dell Secure Connect Gateway - update to 5.24.00.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Maximo Application Suite - addressed in versions 8.7.10, 8.8.6
postgresql-jdbc - addressed in versions 9.4-3.12.1, 42.2.25-150300.3.14.1, 42.2.25-150400.3.12.1
IBM Security Verify Governance - update to 10.0.2.0.3
InfoSphere Data Replication - update to 11.4.0.5 5752
postgresql-jdbc (Red Hat package) - addressed in versions 42.2.3-5.el8_2, 42.2.3-5.el8_6, 42.2.14-3.el8_9, 42.2.14-5.el8_8, 42.2.28-1.el9_0, 42.2.28-1.el9_2, 42.2.28-1.el9_3
postgresql-jdbc-javadoc - update to 42.2.14-3
postgresql-jdbc - update to 42.2.14-3
postgresql-jdbc-javadoc - addressed in versions 42.2.25-150300.3.14.1, 42.2.25-150400.3.12.1
postgresql-jdbc - update to 42.4.1-3
postgresql-jdbc-help - update to 42.4.1-3
postgresql-jdbc-javadoc - update to 42.4.1-3
postgresql-jdbc - update to 42.7.3-1.fc40
IBM Observability with Instana - update to 269
External References
Related Security Bulletins
- SQL injectin in PostgreSQL JDBC driver
- Multiple vulnerabilities in Bosh Release for the UAA
- SQL injection in Openfire
- Multiple vulnerabilities in Rundeck
- SUSE update for postgresql-jdbc
- SUSE update for postgresql-jdbc
- SUSE update for postgresql-jdbc
- openEuler update for postgresql-jdbc
- Fedora 40 update for postgresql-jdbc
- Red Hat Enterprise Linux 8 update for postgresql-jdbc
- Multiple vulnerabilities in IBM Security Verify Information Queue
- Red Hat Enterprise Linux 9 update for postgresql-jdbc
- Bamboo Data Center and Server update for postgresql
- SQL injection in IBM Cloud Pak for AIOps
- SQL injection in IBM Maximo Application Suite
- Red Hat Enterprise Linux 9.2 Extended Update Support update for postgresql-jdbc
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- SQL injection in IBM Tivoli Netcool Impact
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Disconnected Log Collector
- SQL injection in IBM Instana Observability
- Multiple vulnerabilities in Oracle Enterprise Data Quality
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat build of Quarkus 2.13
- Red Hat Enterprise Linux 9.0 Extended Update Support update for postgresql-jdbc
- Multiple vulnerabilities in Red Hat build of Quarkus 3.2
- SQL injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- SQL injection in IBM Watson Discovery
- Red Hat Enterprise Linux 8.2 update for postgresql-jdbc
- SQL injection in IBM Storage Scale
- SQL injection in IBM QRadar SIEM
- Confluence Data Center and Server update for postgresql
- Jira Software Data Center and Server update for postgresql
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Red Hat Enterprise Linux 8.8 Extended Update Support update for postgresql-jdbc
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for postgresql-jdbc
- Multiple vulnerabilities in Dell PowerStoreT OS
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in HPE Telco IP Mediation Application
- IBM InfoSphere Data Replication update for PostgreSQL JDBC Driver
- Anolis OS update for postgresql-jdbc
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for PostgreSQL JDBC Driver