cbcvebase.
CVE-2016-4999
published 2016-08-05

CVE-2016-4999: SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before…

PriorityP258critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.65%
88.4th percentile
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

Affected

14 ranges
VendorProductVersion rangeFixed in
redhatdashbuilder<= 0.5.0
redhatjboss_bpm_suite
redhatjboss_bpm_suite
redhatjboss_bpm_suite
redhatjboss_bpm_suite
redhatjboss_bpm_suite
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_brms_platform

Detection & IOCsextracted from sources · hover to see the quote

  • SQL injection entry point is the getStringParameterSQL method in DefaultDialect.java; monitor for anomalous SQL string filter parameters submitted to Data Set Authoring or Displayer editor UI endpoints
  • Attack vector is a specially-crafted string filter parameter in SQL dataset lookup requests; inspect HTTP requests to Dashbuilder dataset lookup endpoints for SQL metacharacters in string filter fields
  • ·Vulnerability affects Dashbuilder versions before 0.6.0.Beta1, including the versions shipped with Red Hat BPM Suite 6 and Red Hat JBoss BRMS 6; fixed in Red Hat JBoss BPM Suite 6.3.1 (RHSA-2016:1429) and Red Hat JBoss BRMS 6.3.1 (RHSA-2016:1428)

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.