CVE-2017-11467

Publication date

2017-07-20 00:00:00

Family

mitre

State

PUBLISHED

Description

OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.