CVE-2025-61018: An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cau...
An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Security readout for executives and security teams
Plain-English summary
This vulnerability can let a remote attacker crash or disrupt OpenLink Virtuoso Open Source 7.2.11 by sending crafted SQL statements. The published impact is denial of service, not data theft or data modification. The main business risk is outage for systems depending on Virtuoso-backed data services.
Executive priority
Treat as a high-priority availability risk for exposed or business-critical Virtuoso services. Prioritize inventory and access restriction now, then patch or follow vendor guidance when a confirmed fix is available.
Technical view
CVE-2025-61018 affects the sqlo_place_dt_set component in openlink virtuoso-opensource v7.2.11. It is scored CVSS 3.1 7.5: network reachable, low complexity, no privileges, no user interaction, with high availability impact only. It is mapped to CWE-89, but the cited impact is DoS.
Likely exposure
Exposure is most likely where Virtuoso Open Source 7.2.11 is deployed and accepts SQL statements over reachable interfaces. The bundle’s affected-product metadata is incomplete, so teams should verify deployments directly rather than assuming package coverage.
Exploitation context
The source bundle does not show CISA KEV listing or cited evidence of active exploitation. The CVSS vector indicates the issue is remotely reachable without authentication, but sources only support denial-of-service impact.
Researcher notes
Sources identify the vulnerable component and DoS outcome but do not provide a confirmed patch, broad affected-version range, or exploitation evidence. Avoid generalizing beyond Virtuoso Open Source 7.2.11 unless vendor or distribution advisories expand affected versions.
Mitigation direction
Inventory Virtuoso Open Source deployments and identify any version 7.2.11 instances.
Check OpenLink and distribution guidance for a fixed version or official workaround.
Restrict network access to SQL-capable Virtuoso interfaces to trusted sources.
Apply vendor updates once an applicable fixed release is confirmed.
Monitor for crashes or repeated SQL errors against Virtuoso services.
Validation and detection
Confirm whether any deployed Virtuoso instance reports version 7.2.11.
Identify which applications or users can submit SQL statements to Virtuoso.
Review service logs for crashes, restarts, or abnormal SQL error bursts.
Check Red Hat CVE and VEX data for distribution-specific affected status.
Track the GitHub issue for maintainer clarification on fix availability.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.