Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38272
HistoryNov 28, 2022 - 6:39 a.m.

SQL Injection

2022-11-2806:39:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
opendaylight
aaa
sql injection
rolestore.java
auth api

0.001 Low

EPSS

Percentile

30.5%

org.opendaylight.aaa:aaa-idm-store-h2 is vulnerable to SQL Injection attacks. A specifically crafted attack statement through the deleteRole function in RoleStore.java allows a malicious user to inject and execute arbitrary SQL queries on the target system, when the API interface /auth/v1/roles/ is used.

0.001 Low

EPSS

Percentile

30.5%

Related for VERACODE:38272