VYPR
Unrated severityNVD Advisory· Published Dec 10, 2024· Updated Dec 11, 2024

CVE-2024-51165

CVE-2024-51165

Description

SQL injection in JEPAAS 7.2.8 via loadLoginCount dateVal parameter allows remote attackers to retrieve all database information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in JEPAAS 7.2.8 via loadLoginCount dateVal parameter allows remote attackers to retrieve all database information.

Vulnerability

A SQL injection vulnerability exists in JEPAAS version 7.2.8, specifically in the /je/rbac/rbac/loadLoginCount endpoint within the je-core-7.2.8.jar component. The dateVal parameter is directly concatenated into SQL queries without proper sanitization, as demonstrated in the provided code snippet [1]. Affected version: JEPAAS 7.2.8.

Exploitation

An attacker can exploit this vulnerability by sending a maliciously crafted HTTP POST request to the /je/rbac/rbac/loadLoginCount endpoint with a crafted dateVal parameter. No authentication is required if the endpoint is publicly accessible, allowing a remote user to execute arbitrary SQL commands via injection.

Impact

Successful exploitation allows the attacker to retrieve all information stored in the database, leading to complete data disclosure and a severe breach of confidentiality. The attacker can extract sensitive user data, internal records, and other database contents.

Mitigation

As of the publication date (2024-12-10), no official patch has been released for this vulnerability [1]. Users should implement input validation and parameterized queries to mitigate the risk. It is recommended to upgrade to a future patched version once available.

References
  1. CVE-2024-51165

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • JEPAAS/JEPAAScpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: =7.2.8

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.