CVE-2024-32888

CRITICAL

The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enter...

Affects 0 products across 5 vendors.

BCS7.31
CVSS 3.110.0
EPSS0.8%
Percentile52th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical SQL injection vulnerability exists in the Amazon JDBC Driver for Redshift prior to version 2.1.0.28 when using the non-default connection property `preferQueryMode=simple` with vulnerable application code.

BSID: BS-2024-GLOBAL-192466-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-32888?
A critical SQL injection vulnerability exists in the Amazon JDBC Driver for Redshift prior to version 2.1.0.28 when using the non-default connection property `preferQueryMode=simple` with vulnerable application code.
What is the CVSS score for CVE-2024-32888?
CVE-2024-32888 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.8%.
Is CVE-2024-32888 actively exploited?
No confirmed active exploitation of CVE-2024-32888 as of 2026-05-30.
How do I remediate CVE-2024-32888?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-32888?
CVE-2024-32888 affects: Amazon, Platform, Program, Redshift, Simple.
Vulnerability Details
CVE IDCVE-2024-32888
BSIDBS-2024-GLOBAL-192466-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-05-15
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
Domains
CLOUD
SourceNVD
Official Description

The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by injecting malicious SQL code into the application's database queries, potentially leading to unauthorized data access, modification, or deletion.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Amazon —
Platform —
Program —
Redshift —
Simple —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 812 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash0001e69724bd7e54a32bc59cd14d4bb00150fd613c86af7a63bedfe39b5a4c1ab462bb30d5f6797700231d6daed6a86c6a6701de0c0baac18da86ac0dd4ac91b
Related CVEs affecting Amazon
CVE-2012-4249 10.0 The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle To... CVE-2019-3989 9.8 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to ex... CVE-2019-18960 9.8 Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.... CVE-2015-7292 9.8 Stack-based buffer overflow in the havok_write function in drivers/staging/ha... CVE-2019-3984 9.8 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to ex...
View all Amazon CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →