Improper neutralization of special elements used in an sql command (sql injection) in SQL Server allows an authorized attacker to elevate privileges over a network.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sql_server_2016 | Microsoft | 13.0.6300.2 (including) | 13.0.6465.1 (excluding) |
Sql_server_2016 | Microsoft | 13.0.7000.253 (including) | 13.0.7060.1 (excluding) |
Sql_server_2017 | Microsoft | 14.0.1000.169 (including) | 14.0.2080.1 (excluding) |
Sql_server_2017 | Microsoft | 14.0.3006.16 (including) | 14.0.3500.1 (excluding) |
Sql_server_2019 | Microsoft | 15.0.2000.5 (including) | 15.0.2140.1 (excluding) |
Sql_server_2019 | Microsoft | 15.0.4003.23 (including) | 15.0.4440.1 (excluding) |
Sql_server_2022 | Microsoft | 16.0.1000.6 (including) | 16.0.1145.1 (excluding) |
Sql_server_2022 | Microsoft | 16.0.4003.1 (including) | 16.0.4210.1 (excluding) |