CVE-2023-32697: Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
Summary
Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL.
Impacted versions :
3.6.14.1-3.41.2.1 References
https://github.com/xerial/sqlite-jdbc/releases/tag/3.41.2.2
Other sources
SQLite JDBC could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a flaw when JDBC url is attacker controlled. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-32697?
CVE-2023-32697 is a vulnerability in SQLite JDBC that allows a remote authenticated attacker to execute arbitrary code on the system by exploiting a flaw in the JDBC URL.
How does CVE-2023-32697 affect the system?
CVE-2023-32697 can be exploited by a remote attacker to execute arbitrary code on the system by sending a specially crafted request.
What is the severity of CVE-2023-32697?
The severity of CVE-2023-32697 is high, with a CVSS score of 8.8.
Which software versions are affected by CVE-2023-32697?
The affected software versions include org.xerial:sqlite-jdbc version 3.6.14.1 up to (but not including) 3.41.2.2, and IBM QRadar SIEM version 7.5.0 UP6.
How can I fix CVE-2023-32697?
To fix CVE-2023-32697, update to the remedy version 3.41.2.2 for org.xerial:sqlite-jdbc package and update to a version beyond 7.5.0 UP6 for IBM QRadar SIEM.