9.8
CVSSv3

CVE-2019-7164

Published: 20/02/2019 Updated: 03/12/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQLAlchemy up to and including 1.2.17 and 1.3.x up to and including 1.3.0b2 allows SQL Injection via the order_by parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sqlalchemy sqlalchemy 1.3.0

sqlalchemy sqlalchemy

debian debian linux 8.0

debian debian linux 9.0

opensuse backports sle 15.0

opensuse leap 15.0

opensuse leap 15.1

redhat enterprise linux 8.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux eus 8.4

redhat enterprise linux server aus 8.2

redhat enterprise linux server aus 8.4

redhat enterprise linux server tus 8.2

redhat enterprise linux server tus 8.4

oracle communications operations monitor 4.2

oracle communications operations monitor 4.3

Vendor Advisories

Debian Bug report logs - #922669 sqlalchemy: CVE-2019-7164 CVE-2019-7548 (SQL injection) Package: src:sqlalchemy; Maintainer for src:sqlalchemy is Piotr Ożarowski <piotr@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 19 Feb 2019 06:51:02 UTC Severity: grave Tags: security, upstream Fo ...
Synopsis Important: python27:27 security update Type/Severity Security Advisory: Important Topic An update for the python27:27 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syst ...
Synopsis Moderate: python36:36 security update Type/Severity Security Advisory: Moderate Topic An update for the python36:36 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...

Github Repositories

Infrastructure for 10x-dux-app analysis with the vuls.io toolset.

10x Dependency Upgrades Project Background This is the main software and Infrastructure-as-Code repository for the 10x Dependency Upgrade (DUX) Phase 2 project,including an evaluation of just-in-time dependency analysis of software at deployment time using the open-source vuls project The original Phase 1 research and our additive research that led to this prototype can be fou