HTTP: SQL AUTONOMOUS_TRANSACTION Keyword SQL Injection

This signature detects attempts to run SQL queries with high privileges. The PRAGMA AUTONOMOUS_TRANSACTION keyword can be used to run queries as independent. It could also be a false positive. To reduce False Positives, it is strongly recommended that these signatures only be used to inspect traffic from the Internet to your organization's web servers that use SQL backend databases to generate content and not to inspect traffic going from your organization to the Internet.

Extended Description

Attackers may use the AUTONOMOUS_TRANSACTION pragma to execute SQL queries at high a privilege level or run queries independently.

Short Name
HTTP:SQL:INJ:AUTO-TRANS
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
AUTONOMOUS_TRANSACTION Injection Keyword SQL
Release Date
03/03/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?