Zabbix Agent 2
cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*
- >= 6.0.0, <= 6.0.44
- >= 7.0.0, <= 7.0.23
- >= 7.4.0, <= 7.4.7
A vulnerability exists in Zabbix Agent 2 that allows users to inject an Oracle TNS connection string through the 'service' parameter. This injection can cause Agent 2 to connect to an attacker-controlled server, potentially leaking Oracle database credentials if they are stored in a named session.
Exploitation of this vulnerability could lead to unauthorized access to Oracle database credentials, allowing an attacker to impersonate a user or access sensitive data.
Users can update to Zabbix Agent 2 version 6.0.45, 7.0.24, or 7.4.8, depending on their current version. Instructions for updating Zabbix Agent 2 can be found in the Zabbix documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.