Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4999

Опубликовано: 14 июл. 2016
Источник: redhat
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

A security flaw was found in the way Dashbuilder performed SQL datasets lookup requests in the Data Set Authoring UI or the Displayer editor UI. A remote attacker could use this flaw to conduct SQL injection attacks via specially-crafted string filter parameter.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6dashbuilderAffected
Red Hat JBoss BRMS 6dashbuilderAffected
Red Hat JBoss BPMS 6.3FixedRHSA-2016:142914.07.2016
Red Hat JBoss BRMS 6.3FixedRHSA-2016:142814.07.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=1349990Dashbuilder: SQL Injection on data set lookup filters

EPSS

Процентиль: 91%
0.06972
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
nvd
больше 9 лет назад

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

CVSS3: 9.8
github
больше 3 лет назад

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

EPSS

Процентиль: 91%
0.06972
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2