CVE-2019-7164: Debian Linux
Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Oracle Communications Operations Monitor: version 4.2 only; version 4.3 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only
- Sqlalchemy Sqlalchemy: up to and including 1.2.17; version 1.3.0 only
Published 2019-02-20. Last modified 2026-06-17.