Vulnerability Details CVE-2024-52057
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.*, from 5.2.0 before 5.3.*.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-52057
-
cpe:2.3:a:rti:connext_professional:5.2.0
-
cpe:2.3:a:rti:connext_professional:5.2.3
-
cpe:2.3:a:rti:connext_professional:5.3.0
-
cpe:2.3:a:rti:connext_professional:5.3.1.40
-
cpe:2.3:a:rti:connext_professional:5.3.1.41
-
cpe:2.3:a:rti:connext_professional:5.3.1.44
-
cpe:2.3:a:rti:connext_professional:5.3.1.45
-
cpe:2.3:a:rti:connext_professional:6.0.0
-
cpe:2.3:a:rti:connext_professional:6.0.1.25
-
cpe:2.3:a:rti:connext_professional:6.0.1.35
-
cpe:2.3:a:rti:connext_professional:6.0.1.40
-
cpe:2.3:a:rti:connext_professional:6.1.0
-
cpe:2.3:a:rti:connext_professional:6.1.1
-
cpe:2.3:a:rti:connext_professional:6.1.1.2
-
cpe:2.3:a:rti:connext_professional:7.0.0
-
cpe:2.3:a:rti:connext_professional:7.1.0
-
cpe:2.3:a:rti:connext_professional:7.2.0