SQL Injection Vulnerability in Trellix DLP Extension
CVE-2024-9678
4.9MEDIUM
Key Information
- Vendor
- Trellix
- Status
- Dlp Extension
- Vendor
- CVE Published:
- 16 December 2024
Summary
CVE-2024-9678 is a critical SQL Injection vulnerability identified within Trellix's DLP Extension version 11.11.1.3. This security flaw enables unauthorized attackers to execute arbitrary SQL queries on the affected application. If exploited, it poses a significant risk, potentially leading to data breaches, unauthorized access to sensitive information, and command execution. Organizations using the vulnerable version of Trellix DLP Extension should apply necessary updates or patches to mitigate security risks associated with this vulnerability.
Affected Version(s)
DLP Extension = 11.11.1.3
Refferences
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database