Vulnerability Description
New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Newrelic | .Net Agent | <= 6.2.26.0 |
Related Weaknesses (CWE)
References
- https://blog.seanmcelroy.com/2017/05/26/sql-injection-with-new-relic-patched/ExploitThird Party Advisory
- https://blog.seanmcelroy.com/2017/05/26/sql-injection-with-new-relic-patched/ExploitThird Party Advisory
FAQ
What is CVE-2017-9246?
CVE-2017-9246 is a vulnerability with a CVSS score of 9.8 (CRITICAL). New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandl...
How severe is CVE-2017-9246?
CVE-2017-9246 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-9246?
Check the references section above for vendor advisories and patch information. Affected products include: Newrelic .Net Agent.