Description
Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.
References (2)
Core 2
Core References
Various Sources
https://cwe.mitre.org/data/definitions/89.html
Scores
CVSS v3
6.8
EPSS
0.0029
EPSS Percentile
20.9%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (2)
Palantir/com.palantir.srx.prometheus.sls-oracle-sidecar:sls-oracle-sidecar
< 0.544.0
Palantir/com.palantir.srx.prometheus.sls-oracle-sidecar:sls-oracle-sidecar
0.347.0
Published
Nov 21, 2024
Tracked Since
Feb 18, 2026