HIGH
SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors
Published Aug 27, 2009
7.5
HIGHCVSS 2.0
EPSS 1.36%
Description
SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
No data.
OR
- ≤ 4.5.1o
- ≤ 5.0.0k
- ≤ 5.2.0g
- 1.0
- 1.0f
- 1.0g
- 1.1
- 1.1a
- 1.1b
- 1.1c
- 1.1d
- 1.1e
- 1.1f
- 1.5d
- 2.0.1
- 2.0.1a
- 2.0.1c
- 3.0.1
- 3.5
- 3.5.1
- 4.0
- 4.0.1
- 4.1
- 4.2
- 4.2.1
- 4.5.0
- 4.5.0f
- 4.5.1
- 5.0.0
- 5.0.0h
- 5.2a
- 5.2c
- 5.2d
- 5.2e
- 5.2e
- 5.2f
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://jvn.jp/en/jp/JVN31035930/index.html third-party-advisoryx_refsource_JVNPatch
- http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000056.html third-party-advisoryx_refsource_JVNDB
- http://secunia.com/advisories/36423 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.ipa.go.jp/security/vuln/documents/2009/200908_sugarcrm.html x_refsource_MISC
- http://www.securityfocus.com/bid/36118 vdb-entryx_refsource_BID
- http://www.sugarcrm.com/forums/showthread.php?t=50907 x_refsource_CONFIRMPatch
- http://www.sugarcrm.com/forums/showthread.php?t=50953 x_refsource_CONFIRMPatch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2963 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52679 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://jvn.jp/en/jp/JVN31035930/index.html | third-party-advisoryx_refsource_JVNPatch | |
| http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000056.html | third-party-advisoryx_refsource_JVNDB | |
| http://secunia.com/advisories/36423 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.ipa.go.jp/security/vuln/documents/2009/200908_sugarcrm.html | x_refsource_MISC | |
| http://www.securityfocus.com/bid/36118 | vdb-entryx_refsource_BID | |
| http://www.sugarcrm.com/forums/showthread.php?t=50907 | x_refsource_CONFIRMPatch | |
| http://www.sugarcrm.com/forums/showthread.php?t=50953 | x_refsource_CONFIRMPatch | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2963 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/52679 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 27, 2009
Updated Aug 7, 2024
Reserved Aug 27, 2009
Link CVE-2009-2978
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-2963 Assigner mitre
Published Aug 27, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-2963