RULE(RULE ID:336982)

Rule General Information
Release Date: 2022-08-21
Rule Name: Apache Skywalking 8.3.0 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: AApache Skywalking is an APM (Application Performance Monitoring) system designed for distributed systems, particularly for microservices, cloud native, and Docker, Kubernetes, Mesos architectures. Its core is a distributed tracking system. There is an H2 Database SQL injection vulnerability in the GraphQL interface in Apache Skywalking version 8.3.0 and earlier.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.