CVE-2024-12746

CVSS 3.1 Score 8 of 10 (high)

Details

Published Dec 24, 2024
Updated: Dec 26, 2024
CWE ID 89

Summary

CVE-2024-12746 is a SQL injection vulnerability affecting the Amazon Redshift ODBC Driver v2.1.5.0, used on both Windows and Linux systems. This issue enables users to gain escalated privileges through the SQLTables or SQLColumns Metadata APIs. To mitigate the risk, users are advised to upgrade to the driver version 2.1.6.0 or revert to the previously secure version 2.1.4.0. This vulnerability can potentially lead to unauthorized access and data manipulation within an Amazon Redshift database.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Amazon Redshift ODBC Driver

Affected Vendors

  • Amazon.com