CVE-2016-4999
published 2016-08-05CVE-2016-4999: SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before…
PriorityP258critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.65%
88.4th percentile
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | dashbuilder | <= 0.5.0 | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_bpm_suite | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_brms_platform | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →SQL injection entry point is the getStringParameterSQL method in DefaultDialect.java; monitor for anomalous SQL string filter parameters submitted to Data Set Authoring or Displayer editor UI endpoints ↗
- →Attack vector is a specially-crafted string filter parameter in SQL dataset lookup requests; inspect HTTP requests to Dashbuilder dataset lookup endpoints for SQL metacharacters in string filter fields ↗
- ·Vulnerability affects Dashbuilder versions before 0.6.0.Beta1, including the versions shipped with Red Hat BPM Suite 6 and Red Hat JBoss BRMS 6; fixed in Red Hat JBoss BPM Suite 6.3.1 (RHSA-2016:1429) and Red Hat JBoss BRMS 6.3.1 (RHSA-2016:1428) ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Dashbuilder: SQL Injection on data set lookup filters
vendor_redhat·2016-07-14·CVSS 9.8
CVE-2016-4999 [CRITICAL] CWE-89 Dashbuilder: SQL Injection on data set lookup filters
Dashbuilder: SQL Injection on data set lookup filters
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
A security flaw was found in the way Dashbuilder performed SQL datasets lookup requests in the Data Set Authoring UI or the Displayer editor UI. A remote attacker could use this flaw to conduct SQL injection attacks via specially-crafted string filter parameter.
Package: dashbuilder (Red Hat BPM Suite 6) - Affected
Package: dashbuilder (Red Hat JBoss BRMS 6) - Affected
GHSA
GHSA-44p5-rm8g-w75h: SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect
ghsa_unreviewed·2022-05-13
CVE-2016-4999 [CRITICAL] CWE-89 GHSA-44p5-rm8g-w75h: SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/91795https://access.redhat.com/errata/RHSA-2016:1428https://access.redhat.com/errata/RHSA-2016:1429https://bugzilla.redhat.com/show_bug.cgi?id=1349990https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524bhttps://issues.jboss.org/browse/DASHBUILDE-113http://www.securityfocus.com/bid/91795https://access.redhat.com/errata/RHSA-2016:1428https://access.redhat.com/errata/RHSA-2016:1429https://bugzilla.redhat.com/show_bug.cgi?id=1349990https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524bhttps://issues.jboss.org/browse/DASHBUILDE-113
2016-08-05
Published