CVE-2017-11467: Orientdb

Critical severity, CVSS 9.8. EPSS: 73.1% chance of exploitation in the next 30 days.

OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.

Affected products

  • Orientdb Orientdb: up to and including 2.2.22

Published 2017-07-20. Last modified 2026-06-17.