First published: Tue Jun 13 2017(Updated: )
New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/NewRelic.Agent | <6.3.123.0 | 6.3.123.0 |
Newrelic .net Agent | <=6.2.26.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9246 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2017-9246, upgrade the New Relic .NET Agent to version 6.3.123.0 or later.
CVE-2017-9246 affects New Relic .NET Agent versions up to 6.3.123.0.
CVE-2017-9246 is a SQL injection vulnerability that can expose applications to serious security risks.
The impact of CVE-2017-9246 can include unauthorized access to database information and manipulation of data.