SQL injection in Postgresql JDBC Driver - CVE-2024-1597
Published: March 4, 2024 / Updated: March 5, 2024
Postgresql JDBC Driver
Cloud Pak for Security (CP4S)
Jira Software Server
IBM Qradar SIEM
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Server Applications Module
openSUSE Leap
openEuler
Fedora
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Security Verify Information Queue
PowerStore T
Security QRadar EDR
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
InfoSphere Data Replication
QRadar Suite
Red Hat build of Quarkus
Confluence Data Center
IBM Tivoli Netcool Impact
Bamboo Server
Jira Software Data Center
Oracle Enterprise Data Quality
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
Dell Secure Connect Gateway
HPE Telco IP Mediation E-Media
IBM Maximo Application Suite
IBM Security Verify Governance
IBM Observability with Instana
Openfire
Rundeck
Confluence Server
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
postgresql-jdbc
postgresql-jdbc (Red Hat package)
postgresql-jdbc-javadoc
postgresql-jdbc-help
Bosh Release for the UAA
Red Hat OpenShift Serverless
IBM Disconnected Log Collector
IBM Storage Scale System
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data when using the "PreferQueryMode=SIMPLE" option. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.