CVE-2023-46954: Relativity Relativityone

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

Affected products

  • Relativity Relativityone: before 12.4.537.3 (fixed in 12.4.537.3); version 12.4.537.3 only

Published 2023-11-03. Last modified 2026-06-17.