Lucene search

K
vulnrichmentApacheVULNRICHMENT:CVE-2024-36263
HistoryJun 12, 2024 - 2:05 p.m.

CVE-2024-36263 Apache Submarine Server Core: SQL injection

2024-06-1214:05:00
CWE-89
apache
github.com
1
cve-2024-36263
apache submarine server core
sql injection

AI Score

7.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

UNSUPPORTED WHEN ASSIGNED Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Apache Submarine Server Core.

This issue affects Apache Submarine Server Core: all versions.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:apache:submarine:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apache",
    "product": "submarine",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "semver",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

7.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-36263