We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.
Reserved 2025-06-22 | Published 2025-07-19 | Updated 2025-07-19 | Assigner mitreCWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
onelogin.service-now.com/...a0d76d70db185340d5505eea4b96199f
Support options