LiveActive security incident?Get immediate response
CVE Record

CVE-2017-9246: New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving f...

New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This CVE describes a New Relic .NET Agent flaw where the monitoring agent could introduce SQL injection risk into otherwise safe .NET applications when Slow Queries was used. The issue affected versions before 6.3.123.0. Public severity scoring is not provided in the source bundle.

Executive priority

Treat this as a targeted legacy exposure review. The issue can undermine application SQL safety through monitoring software, but the provided sources lack severity scoring and active exploitation evidence. Prioritize upgrade verification where older New Relic .NET Agents remain deployed.

Technical view

New Relic .NET Agent before 6.3.123.0 failed to escape quotes correctly in Slow Queries handling. The CVE description cites SQL injection through mishandled quoted SQL, including an INSERT VALUES case and bypass of a SET SHOWPLAN_ALL ON protection mechanism.

Likely exposure

Exposure is likely limited to .NET applications running New Relic .NET Agent versions earlier than 6.3.123.0, especially where Slow Queries instrumentation was enabled. The bundle does not identify specific application frameworks, databases, or deployment environments beyond the agent.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation evidence. A public researcher blog is referenced and indicates the issue was patched, but the bundle provides no exploit prevalence, attack timeline, or observed campaign data.

Researcher notes

Key uncertainty is operational scope: the CVE names the agent and Slow Queries behavior but gives no CVSS, CWE, database matrix, or confirmed exploitation. Validate by version inventory and configuration review, not by reproducing the flaw in production.

Mitigation direction

  • Inventory .NET applications using New Relic .NET Agent.
  • Upgrade New Relic .NET Agent to 6.3.123.0 or later.
  • Check New Relic guidance for any additional configuration recommendations.
  • Review whether Slow Queries was enabled on affected deployments.
  • Prioritize systems handling sensitive or high-value database records.

Validation and detection

  • Confirm installed New Relic .NET Agent versions across production and staging.
  • Verify affected hosts no longer run versions before 6.3.123.0.
  • Check application configuration for Slow Queries usage.
  • Review database and application logs for unusual SQL errors or quote-handling anomalies.
  • Document any remaining unsupported or legacy monitored applications.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2017-9246 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.