CVE-2024-52057

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
13/12/2024
Last modified:
02/10/2025

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.*, from 5.2.0 before 5.3.*.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* 5.2.0 (including) 6.1.2.17 (excluding)
cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:* 7.0.0 (including) 7.3.0 (excluding)


References to Advisories, Solutions, and Tools