Vulnerabilidad · Publicado 28/08/2026 · Actualizado 29/08/2026
Un atacante puede enviar consultas SQL malformadas a través del controlador ODBC de MongoDB Connector for BI, especificando nombres de cursor que exceden los límites internos del búfer. Esto provoca sobrescritura de memoria adyacente, potencialmente causando denial of service (DoS) o ejecución de código arbitrario en aplicaciones que integren este conector. Afecta directamente a plataformas de análisis y Business Intelligence que dependan de este driver en entornos LATAM.
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that buffer is overwritten with user-supplied content. This can terminate the hosting application process and may allow unintended code to run within it.
Score: 8.8/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-121
Publicado en NIST NVD.