PT-2024-8800 · Intel · Intel Neural Compressor
Published
2024-11-12
·
Updated
2024-11-15
·
CVE-2024-39368
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Intel(R) Neural Compressor versions prior to v3.0
Description:
The issue is related to improper neutralization of special elements used in an SQL command, also known as 'SQL Injection', in some Intel(R) Neural Compressor software. This may allow an authenticated user to potentially enable escalation of privilege via adjacent access. The vulnerability can be exploited by a remote attacker to elevate their privileges.
Recommendations:
For versions prior to v3.0, upgrade to version v3.0 or later to prevent privilege escalation. As a temporary workaround, consider restricting access to the SQL command functionality until a patch is available. Avoid using the vulnerable software for sensitive operations until the issue is resolved.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Neural Compressor