CVE-2022-0757: Rapid7 Nexpose SQL Injection
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the SQL injection vulnerability in Rapid7 Nexpose?
The vulnerability ID for the SQL injection vulnerability in Rapid7 Nexpose is CVE-2022-0757.
What is the severity of CVE-2022-0757?
The severity of CVE-2022-0757 is high.
Which versions of Rapid7 Nexpose are affected by CVE-2022-0757?
Rapid7 Nexpose versions 6.6.93 and earlier are affected by CVE-2022-0757.
How does the SQL injection vulnerability in Rapid7 Nexpose work?
The SQL injection vulnerability in Rapid7 Nexpose allows an authenticated attacker to inject SQL code by manipulating the "ANY" and "OR" operators in the SearchCriteria.
Is there a fix available for CVE-2022-0757 in Rapid7 Nexpose?
Yes, a fix for CVE-2022-0757 in Rapid7 Nexpose is available. It is recommended to update to a version later than 6.6.93.