Security readout for executives and security teams
Plain-English summary
This CVE describes a New Relic .NET Agent flaw where the monitoring agent could introduce SQL injection risk into otherwise safe .NET applications when Slow Queries was used. The issue affected versions before 6.3.123.0. Public severity scoring is not provided in the source bundle.
Executive priority
Treat this as a targeted legacy exposure review. The issue can undermine application SQL safety through monitoring software, but the provided sources lack severity scoring and active exploitation evidence. Prioritize upgrade verification where older New Relic .NET Agents remain deployed.
Technical view
New Relic .NET Agent before 6.3.123.0 failed to escape quotes correctly in Slow Queries handling. The CVE description cites SQL injection through mishandled quoted SQL, including an INSERT VALUES case and bypass of a SET SHOWPLAN_ALL ON protection mechanism.
Likely exposure
Exposure is likely limited to .NET applications running New Relic .NET Agent versions earlier than 6.3.123.0, especially where Slow Queries instrumentation was enabled. The bundle does not identify specific application frameworks, databases, or deployment environments beyond the agent.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. A public researcher blog is referenced and indicates the issue was patched, but the bundle provides no exploit prevalence, attack timeline, or observed campaign data.
Researcher notes
Key uncertainty is operational scope: the CVE names the agent and Slow Queries behavior but gives no CVSS, CWE, database matrix, or confirmed exploitation. Validate by version inventory and configuration review, not by reproducing the flaw in production.
Mitigation direction
- Inventory .NET applications using New Relic .NET Agent.
- Upgrade New Relic .NET Agent to 6.3.123.0 or later.
- Check New Relic guidance for any additional configuration recommendations.
- Review whether Slow Queries was enabled on affected deployments.
- Prioritize systems handling sensitive or high-value database records.
Validation and detection
- Confirm installed New Relic .NET Agent versions across production and staging.
- Verify affected hosts no longer run versions before 6.3.123.0.
- Check application configuration for Slow Queries usage.
- Review database and application logs for unusual SQL errors or quote-handling anomalies.
- Document any remaining unsupported or legacy monitored applications.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Database behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2017-9246 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://blog.seanmcelroy.com/2017/05/26/sql-injection-with-new-relic-patched/CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
