CVE-2019-19317: SQL Injection
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
Other sources
SQLite is vulnerable to a denial of service, caused by an error in lookupName in resolve.c. By providing specially crafted input, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-19317?
CVE-2019-19317 is a vulnerability in SQLite that can be exploited by a remote attacker to cause the application to crash.
What is the severity of CVE-2019-19317?
The severity of CVE-2019-19317 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2019-19317?
The affected software includes IBM Data Risk Manager (versions up to and including 2.0.6), SQLite (version 3.30.1), Netapp Cloud Backup, NetApp ONTAP Select Deploy administration utility, Oracle MySQL Workbench (versions up to and including 8.0.19), and Siemens Sinec Infrastructure Network Services (versions up to but not including 1.0.1.1).
How can I fix CVE-2019-19317 in IBM Data Risk Manager?
To fix CVE-2019-19317 in IBM Data Risk Manager, you can apply the patch provided by IBM. You can find the patch on the IBM Support Fix Central website.
Where can I find more information about CVE-2019-19317?
You can find more information about CVE-2019-19317 on the Siemens ProductCERT website and the GitHub page of SQLite.