This document explains how to patch a system for SQL injection vulnerability in the SQL Server Transport using hotfix release 1.2.5.
This vulnerability can be fixed by upgrading the SQL Server Transport package that is being used. The package can be updated by issuing the following command in the Package Manager Console within Visual Studio:
Update-Package NServiceBus.SqlServer -Version 1.2.5
After the package has been updated, all affected endpoints need to be rebuilt and redeployed.