CVE-2019-7164: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Communications Operations Monitor: version 4.2 only; version 4.3 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only
  • Sqlalchemy Sqlalchemy: up to and including 1.2.17; version 1.3.0 only

Published 2019-02-20. Last modified 2026-06-17.