SQL Injection Vulnerability in Trellix DLP Extension

CVE-2024-9678

4.9MEDIUM

Key Information

Vendor
Trellix
Status
Dlp Extension
Vendor
CVE Published:
16 December 2024

Summary

CVE-2024-9678 is a critical SQL Injection vulnerability identified within Trellix's DLP Extension version 11.11.1.3. This security flaw enables unauthorized attackers to execute arbitrary SQL queries on the affected application. If exploited, it poses a significant risk, potentially leading to data breaches, unauthorized access to sensitive information, and command execution. Organizations using the vulnerable version of Trellix DLP Extension should apply necessary updates or patches to mitigate security risks associated with this vulnerability.

Affected Version(s)

DLP Extension = 11.11.1.3

Refferences

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.