Rapid7

vulnerability

SUSE: CVE-2019-7164: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Feb 19, 2019
Added
Sep 3, 2019
Modified
Feb 4, 2022

Description

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Solutions

suse-upgrade-python-sqlalchemy-docsuse-upgrade-python2-sqlalchemysuse-upgrade-python3-sqlalchemy
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.