CVE-2024-57654
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-57654 is a newly discovered vulnerability affecting the qst_vec_get_int64 component in openlink virtuoso-opensource version 7.2.11. Maliciously crafted SQL statements can trigger a Denial of Service (DoS) condition in this component, causing the database server to become unresponsive and preventing legitimate users from accessing the system. Attackers may exploit this vulnerability to disrupt services and cause significant downtime for affected organizations. It is strongly recommended that users of openlink virtuoso-opensource version 7.2.11 apply the necessary patches as soon as possible to mitigate the risk of a successful DoS attack.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Virtuoso-Opensource
Affected Vendors
- OpenLink Software Inc