Lucene search

K
nvd[email protected]NVD:CVE-2020-35527
HistorySep 01, 2022 - 6:15 p.m.

CVE-2020-35527

2022-09-0118:15:08
CWE-119
web.nvd.nist.gov
8
sqlite
3.31.1
out of bounds access
alter table
nested from clause

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.5%

In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

Affected configurations

Nvd
Node
sqlitesqliteMatch3.31.1
Node
netappontap_select_deploy_administration_utilityMatch-
VendorProductVersionCPE
sqlitesqlite3.31.1cpe:2.3:a:sqlite:sqlite:3.31.1:*:*:*:*:*:*:*
netappontap_select_deploy_administration_utility-cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.5%