Home
MEDIUM: 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:NDefault status
unaffected
Any version before 2025.2.0
affected
Description
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 2025.2.0
References
onelogin.service-now.com/...a0d76d70db185340d5505eea4b96199f
onelogin.service-now.com/...a0d76d70db185340d5505eea4b96199f