CVE-2024-32888
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enter...
Affects 0 products across 5 vendors.
Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical SQL injection vulnerability exists in the Amazon JDBC Driver for Redshift prior to version 2.1.0.28 when using the non-default connection property `preferQueryMode=simple` with vulnerable application code.
BSID: BS-2024-GLOBAL-192466-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-32888?
What is the CVSS score for CVE-2024-32888?
Is CVE-2024-32888 actively exploited?
How do I remediate CVE-2024-32888?
What systems are affected by CVE-2024-32888?
| CVE ID | CVE-2024-32888 |
|---|---|
| BSID | BS-2024-GLOBAL-192466-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-05-15 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability by injecting malicious SQL code into the application's database queries, potentially leading to unauthorized data access, modification, or deletion.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Amazon | — | — |
| Platform | — | — |
| Program | — | — |
| Redshift | — | — |
| Simple | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 0001e69724bd7e54a32bc59cd14d4bb00150fd613c86af7a63bedfe39b5a4c1ab462bb30d5f6797700231d6daed6a86c6a6701de0c0baac18da86ac0dd4ac91b |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →