S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-9483 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Apache SkyWalking affects v. 6.0.0 to 6.6.0, 7.0.0.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-9483
7.5
CVSS

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implementations don't use the appropriate way to set SQL parameters.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache SkyWalkingby n/a
Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0
Updated Aug 21, 2026View on NVD →
Detail

Apache SkyWalking is a powerful open source observability analysis platform that is widely used for application and infrastructure monitoring. It provides the ability to understand the performance characteristics of distributed systems, including service topology map, service instance health, and metrics analysis. In addition, it offers end-to-end tracing of requests and distributed transaction monitoring, as well as integration with other tools such as Prometheus, Elasticsearch, and Zipkin.

CVE-2020-9483 is a critical vulnerability that was recently detected in Apache SkyWalking versions 6.0.0 through 6.6.0 and 7.0.0. The vulnerability is related to the storage implementations of H2, MySQL, and TiDB and involves a SQL injection attack that allows unauthorized access to data outside the intended scope. The problem arises from the use of inappropriate methods to set SQL parameters, which exposes the database to SQL injection attacks.

When exploited, the CVE-2020-9483 vulnerability in Apache SkyWalking can lead to serious consequences. Attackers can gain access to sensitive data stored in the database, such as user credentials, payment information, and other confidential information. By manipulating the SQL statements used by the platform, attackers can execute arbitrary SQL commands and extract or modify data stored in the vulnerable database. This is a significant threat to the integrity and confidentiality of sensitive data.

At s4e.io, we provide advanced vulnerability scanning and management tools that can help you stay ahead of threats like CVE-2020-9483. Our platform offers comprehensive monitoring of digital assets across all platforms and features easy-to-use dashboards and reporting to help you stay informed about threat activity. With s4e.io, you can take control over your security and protect your digital assets from the latest threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability in Apache SkyWalking, users can take the following precautions:

  • Install the latest security patches released by Apache SkyWalking and update to the latest version.
  • Ensure that the database system used for Apache SkyWalking is properly configured for security and has secure passwords or authentication settings.
  • Implement input sanitization and parameterization to prevent SQL injection attacks.
  • Monitor Apache SkyWalking logs for suspicious activity or access attempts that may indicate an ongoing attack.
  • Consider setting up a firewall or network security system to detect and block malicious traffic targeting Apache SkyWalking.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.