openlink virtuoso-opensource
cpe:2.3:a:openlinksw:virtuoso:*:*:*:*:*:*:*
- 7.2.11
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the itc_set_param_row component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the Virtuoso server to crash.
The vulnerability can be reproduced by creating a SQL table with a specific check constraint, then inserting data into the table using a crafted SQL statement that exploits the vulnerability. This can be done using the Virtuoso command-line interface (isql) after starting a Virtuoso Docker container with the DBA password set to 'dba'.
Users can update to OpenLink Virtuoso version 7.2.12 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.