CVE-2019-7548: Debian Linux

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Communications Operations Monitor: version 4.2 only; version 4.3 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only
  • Sqlalchemy Sqlalchemy: version 1.2.17 only

Published 2019-02-06. Last modified 2026-06-17.