Anchore Enterprise
cpe:2.3:a:anchore:anchore:*:*:*:*:*:*:*
- < 5.25.1
A SQL injection vulnerability has been identified in the GraphQL Reports API of Anchore Enterprise, affecting versions prior to 5.25.1. This vulnerability allows authenticated attackers with access to the GraphQL API to execute arbitrary SQL commands, potentially leading to unauthorized modifications of data in the Anchore Enterprise database.
Exploitation of this vulnerability allows for authenticated SQL injection, with the potential to alter database contents.
Users can upgrade to Anchore Enterprise version 5.25.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.