MidnightBSD

Advisories for newrelic

CVE-2013-0284 MEDIUM

Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
newrelic ruby_agent 3.4.0
newrelic ruby_agent 3.5.1.14
newrelic ruby_agent 3.4.2
newrelic ruby_agent 3.3.0
newrelic ruby_agent 3.5.0.1
newrelic ruby_agent 3.5.0
newrelic ruby_agent 3.3.2
newrelic ruby_agent 3.3.4
newrelic ruby_agent 3.2.0
newrelic ruby_agent 3.4.2.1
newrelic ruby_agent 3.3.3
newrelic ruby_agent 3.5.1
newrelic ruby_agent 3.3.1
newrelic ruby_agent 3.4.1
newrelic ruby_agent 3.3.5
newrelic ruby_agent 3.3.4.1
newrelic ruby_agent 3.3.2.1
newrelic ruby_agent 3.5.2
newrelic ruby_agent 3.4.0.1
CVE-2017-9246 HIGH

New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
newrelic .net_agent *