// For flags

CVE-2016-4999

Dashbuilder: SQL Injection on data set lookup filters

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

Vulnerabilidad de inyección SQL en el método getStringParameterSQL en main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java en Dashbuilder en versiones anteriores a 0.6.0.Beta1 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de un filtro de búsqueda de conjunto de datos en (1) Data Set Authoring o (2) Displayer editor UI.

A security flaw was found in the way Dashbuilder performed SQL datasets lookup requests in the Data Set Authoring UI or the Displayer editor UI. A remote attacker could use this flaw to conduct SQL injection attacks via specially-crafted string filter parameter.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-05-24 CVE Reserved
  • 2016-07-14 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Dashbuilder
Search vendor "Redhat" for product "Dashbuilder"
<= 0.5.0
Search vendor "Redhat" for product "Dashbuilder" and version " <= 0.5.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Bpm Suite
Search vendor "Redhat" for product "Jboss Bpm Suite"
6.0.0
Search vendor "Redhat" for product "Jboss Bpm Suite" and version "6.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Bpm Suite
Search vendor "Redhat" for product "Jboss Bpm Suite"
6.0.1
Search vendor "Redhat" for product "Jboss Bpm Suite" and version "6.0.1"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Bpm Suite
Search vendor "Redhat" for product "Jboss Bpm Suite"
6.0.3
Search vendor "Redhat" for product "Jboss Bpm Suite" and version "6.0.3"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Bpm Suite
Search vendor "Redhat" for product "Jboss Bpm Suite"
6.1
Search vendor "Redhat" for product "Jboss Bpm Suite" and version "6.1"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Bpm Suite
Search vendor "Redhat" for product "Jboss Bpm Suite"
6.1.2
Search vendor "Redhat" for product "Jboss Bpm Suite" and version "6.1.2"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
5.0.0
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "5.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
5.3.1
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "5.3.1"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
6.0.0
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "6.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
6.0.1
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "6.0.1"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
6.0.2
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "6.0.2"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
6.0.3
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "6.0.3"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
6.1
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "6.1"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Brms Platform
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform"
6.3
Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version "6.3"
-
Affected