F5-K000148494: SQL Injection
Published Nov 12, 2024
·Updated
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
Affected Software
4 affected components
F5 BIG-IP=3
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 BIG-IQ Centralized Management>=8.2.0<=8.4.0
Event History
Nov 12, 2024
Advisory Published
via F5·02:54 AM
Data Sourced
via F5·02:54 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000148494?
The severity of F5-K000148494 is classified as high due to the potential impact on data integrity.
2
How do I fix F5-K000148494?
You can fix F5-K000148494 by upgrading to a version of SQLite that is 3.32.0 or later.
3
Which F5 products are affected by F5-K000148494?
F5-K000148494 affects F5 BIG-IP versions between 15.1.0 and 15.1.10, 16.1.0 and 16.1.5, 17.1.0 and 17.1.1, as well as F5 BIG-IQ Centralized Management versions from 8.2.0 to 8.3.0.
4
What vulnerabilities does F5-K000148494 address?
F5-K000148494 addresses vulnerabilities related to renaming virtual tables to shadow tables in SQLite.
5
When was F5-K000148494 reported?
F5-K000148494 was reported in 2023 as an issue affecting specific versions of F5 software.