AWS records
3 published records for vendor aws.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-32888No exploit | Amazon JDBC Driver for Redshift SQL Injection via line comment generationaws · amazon-redshift-jdbc-driver · CWE-89 | Critical10.0 | — | 0.8% | May 14, 2024 |
31Monitor | CVE-2024-34073No exploit | Command Injection in sagemaker-python-sdkaws · sagemaker-python-sdk · CWE-78 | High7.8 | — | 1.2% | May 3, 2024 |
31Monitor | CVE-2024-34072No exploit | Deserialization of Untrusted Data in sagemaker-python-sdkaws · sagemaker-python-sdk · CWE-502 | High7.8 | — | 0.4% | May 3, 2024 |
- CVE-2024-3288840Plan
Amazon JDBC Driver for Redshift SQL Injection via line comment generation
CriticalCVSS 10.0No exploitEPSS 1%aws · amazon-redshift-jdbc-driverMay 14, 2024
- CVE-2024-3407331Monitor
Command Injection in sagemaker-python-sdk
HighCVSS 7.8No exploitEPSS 1%aws · sagemaker-python-sdkMay 3, 2024
- CVE-2024-3407231Monitor
Deserialization of Untrusted Data in sagemaker-python-sdk
HighCVSS 7.8No exploitEPSS 0%aws · sagemaker-python-sdkMay 3, 2024