6.8
CVSSv2

CVE-2019-7548

Published: 06/02/2019 Updated: 30/11/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sqlalchemy sqlalchemy 1.2.17

debian debian linux 8.0

debian debian linux 9.0

opensuse backports sle 15.0

opensuse leap 15.0

opensuse leap 15.1

redhat enterprise linux 8.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux eus 8.4

redhat enterprise linux server aus 8.2

redhat enterprise linux server aus 8.4

redhat enterprise linux server tus 8.2

redhat enterprise linux server tus 8.4

oracle communications operations monitor 4.2

oracle communications operations monitor 4.3

Vendor Advisories

Debian Bug report logs - #922669 sqlalchemy: CVE-2019-7164 CVE-2019-7548 (SQL injection) Package: src:sqlalchemy; Maintainer for src:sqlalchemy is Piotr Ożarowski <piotr@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 19 Feb 2019 06:51:02 UTC Severity: grave Tags: security, upstream Fo ...
Synopsis Important: python27:27 security update Type/Severity Security Advisory: Important Topic An update for the python27:27 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syst ...
Synopsis Moderate: python36:36 security update Type/Severity Security Advisory: Moderate Topic An update for the python36:36 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
SQLAlchemy 1217 has SQL Injection when the group_by parameter can be controlled ...