Vulnerability Description
Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert settings in the UI. This is fixed in 9.2.15.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red-Gate | Sql Monitor | >= 9.0.13, <= 9.2.14 |
Related Weaknesses (CWE)
References
- https://www.red-gate.com/privacy-and-security/vulnerabilities/2020-02-19-sql-monVendor Advisory
- https://www.red-gate.com/privacy-and-security/vulnerabilities/2020-02-19-sql-monVendor Advisory
FAQ
What is CVE-2020-9318?
CVE-2020-9318 is a vulnerability with a CVSS score of 7.2 (HIGH). Red Gate SQL Monitor 9.0.13 through 9.2.14 allows an administrative user to perform a SQL injection attack by configuring the SNMP alert settings in the UI. This is fixed in 9.2.15.
How severe is CVE-2020-9318?
CVE-2020-9318 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9318?
Check the references section above for vendor advisories and patch information. Affected products include: Red-Gate Sql Monitor.