CVE-2017-9246: SQL Injection
New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLANALL ON protection mechanism.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9246?
CVE-2017-9246 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2017-9246?
To fix CVE-2017-9246, upgrade the New Relic .NET Agent to version 6.3.123.0 or later.
Which versions are affected by CVE-2017-9246?
CVE-2017-9246 affects New Relic .NET Agent versions up to 6.3.123.0.
What type of vulnerability is CVE-2017-9246?
CVE-2017-9246 is a SQL injection vulnerability that can expose applications to serious security risks.
What is the impact of CVE-2017-9246?
The impact of CVE-2017-9246 can include unauthorized access to database information and manipulation of data.