Vulnerability record · CVE-2017-11467 · published 20 July 2017
CVE-2017-11467: OrientDB privilege bypass in where/fetchplan/order by leads to OS command execution
Orientdb · Orientdb
OrientDB through 2.2.22 fails to enforce privilege requirements when the where, fetchplan, or order by clauses are used, letting a remote attacker bypass authorization checks. Because the bypass reaches command execution paths, it allows arbitrary OS command execution on the database host. This is a critical pre-auth flaw in a database server that often holds sensitive data and runs with elevated service privileges.
Description
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote OS command execution with a CVSS of 9.8 and very high EPSS makes this an urgent patch-or-isolate case.
What it is
OrientDB through 2.2.22 fails to enforce privilege requirements when the where, fetchplan, or order by clauses are used, letting a remote attacker bypass authorization checks. Because the bypass reaches command execution paths, it allows arbitrary OS command execution on the database host. This is a critical pre-auth flaw in a database server that often holds sensitive data and runs with elevated service privileges.
Impact
An unauthenticated remote attacker can execute arbitrary operating system commands on the OrientDB server, leading to full host compromise, data theft, and lateral movement into connected systems.
Attack surface
Reachable over the network via crafted requests to the OrientDB service; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.73, 99.4th percentile) and a public exploit reference is tagged, indicating active interest and available exploit code.
What to do
- Upgrade OrientDB to 2.2.23 or later, which the vendor release notes indicate fixes this issue.
- If immediate upgrade is not possible, restrict network access to OrientDB ports to trusted hosts only and never expose the service to the internet.
- Run the OrientDB service under a low-privilege dedicated account to limit the impact of command execution.
- Audit database users and privileges, and remove or disable unused accounts and remote interfaces.
- Monitor vendor advisories for further guidance and apply any additional hardening recommended for the 2.2.x line.
Detection
- Inspect OrientDB server logs for requests containing where, fetchplan, or order by clauses with unusual or shell-like payloads.
- Monitor for unexpected child processes spawned by the OrientDB service account (for example shells, curl, wget, or scripting interpreters).
- Alert on outbound network connections originating from the database host to unfamiliar destinations.
- Review file integrity and command history on OrientDB hosts for signs of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.heavensec.org/?p=1703 | ExploitThird Party AdvisoryURL Repurposed |
| https://github.com/orientechnologies/orientdb/wiki/OrientDB-2.2-Release-Notes#2223---july-11-2017 | Third Party Advisory |
| http://www.heavensec.org/?p=1703 | ExploitThird Party AdvisoryURL Repurposed |
| https://github.com/orientechnologies/orientdb/wiki/OrientDB-2.2-Release-Notes#2223---july-11-2017 | Third Party Advisory |
Track CVE-2017-11467 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.