660b15ecf9caf7001ee32c7e Shutterstock 2010923726

CISA and FBI highlight prevalence of SQLi vulnerabilities

April 1, 2024
Secure by Design alert designed to eliminate SQL injection vulnerabilities in software

The Cybersecurity & Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released a joint Secure by Design alert, eliminating SQL injection vulnerabilities in software. The alert was crafted in response to a recent, well-publicized exploitation of SQL injection (SQLi) defects in a managed file transfer application that impacted thousands of organizations. Additionally, the alert highlights the prevalence of this class of vulnerability.

Despite widespread knowledge and documentation of SQLi vulnerabilities over the past two decades, along with the availability of effective mitigations, software manufacturers continue to develop products with this defect, which puts many customers at risk.

CISA and the FBI urge senior executives at technology manufacturing companies to mount a formal review of their code to determine its susceptibility to SQLi compromises. If found vulnerable, senior executives should ensure their organizations’ software developers begin immediate implementation of mitigations to eliminate this entire class of defect from all current and future software products.

Sponsored Recommendations

IDEC Push-In Terminals make control panel wiring quicker and easier

Push-in terminals simplify the wiring of control panels for equipment manufacturers that have many control devices in the panel. The push-in terminal also reduces manufacturing...

Addressing Harsh Environmental Challenges with Technology

Discover why rugged HMI technology is crucial for enhancing machine performance and reliability in harsh environments. Learn about our high-quality, certified solutions designed...

2024 State of Technology Report: Motors, Drives & Motion

Motion makes manufacturing move. Motors and drives are at the core of industrial operations. Without them, production comes to a halt. This new State of Technology Report from...

Case Study: Conveyor Solution for Unique Application

Find out how the Motion Automation Intelligence Conveyor Engineering team provided a new and reliable conveyance solution that helped a manufacturer turn downtime into uptime....