216.73.216.6

CVE-2024-12746

· Published 24/12/2024 17:15 · Modified 26/12/2024 15:15

Labels: CVE-2024-12746 2024-12-24CVE-2024-12746CWE-89ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
24/12/2024 17:15
Modified
26/12/2024 15:15
Author
Creator
CVSS
8.0 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

References