CVE-2024-57646

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 14, 2025
Updated: Jan 15, 2025
CWE ID 89

Summary

CVE-2024-57646 is a newly identified vulnerability affecting the psiginfo component in openlink virtuoso-opensource version 7.2.11. This issue permits attackers to initiate a Denial of Service (DoS) attack via specifically crafted SQL statements. The vulnerability arises due to an unhandled condition within the component, providing malicious actors an opportunity to cause service interruption. To mitigate this risk, users are encouraged to upgrade to the latest version of openlink virtuoso-opensource or apply relevant patches as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Virtuoso-Opensource

Affected Vendors

  • OpenLink Software Inc