// For flags

CVE-2020-9417

TIBCO Foresight SQL Injection

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.

El componente de reporte Transaction Insight de TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight y TIBCO Foresight Transaction Insight Healthcare Edition, de TIBCO Software Inc, contiene una vulnerabilidad que teóricamente permite a un atacante autenticado llevar a cabo una inyección SQL. Las versiones afectadas son TIBCO Foresight Archive and Retrieval System de TIBCO Software Inc.: versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Operational Monitor : versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versiones 5.1.0 y posteriores, versión 5.2.0, TIBCO Foresight Transaction Insight: versiones 5.1.0 y anteriores, versión 5.2.0, y TIBCO Foresight Transaction Insight Healthcare Edition: versiones 5.1.0 y anteriores, versión 5.2.0

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-02-26 CVE Reserved
  • 2020-10-20 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tibco
Search vendor "Tibco"
Foresight Archive And Retrieval System
Search vendor "Tibco" for product "Foresight Archive And Retrieval System"
<= 5.1.0
Search vendor "Tibco" for product "Foresight Archive And Retrieval System" and version " <= 5.1.0"
-
Affected
Tibco
Search vendor "Tibco"
Foresight Archive And Retrieval System
Search vendor "Tibco" for product "Foresight Archive And Retrieval System"
5.2.0
Search vendor "Tibco" for product "Foresight Archive And Retrieval System" and version "5.2.0"
-
Affected
Tibco
Search vendor "Tibco"
Foresight Operational Monitor
Search vendor "Tibco" for product "Foresight Operational Monitor"
<= 5.1.0
Search vendor "Tibco" for product "Foresight Operational Monitor" and version " <= 5.1.0"
-
Affected
Tibco
Search vendor "Tibco"
Foresight Operational Monitor
Search vendor "Tibco" for product "Foresight Operational Monitor"
5.2.0
Search vendor "Tibco" for product "Foresight Operational Monitor" and version "5.2.0"
-
Affected
Tibco
Search vendor "Tibco"
Foresight Transaction Insight
Search vendor "Tibco" for product "Foresight Transaction Insight"
<= 5.1.0
Search vendor "Tibco" for product "Foresight Transaction Insight" and version " <= 5.1.0"
-
Affected
Tibco
Search vendor "Tibco"
Foresight Transaction Insight
Search vendor "Tibco" for product "Foresight Transaction Insight"
5.2.0
Search vendor "Tibco" for product "Foresight Transaction Insight" and version "5.2.0"
-
Affected
Tibco
Search vendor "Tibco"
Foresight Archive And Retrieval System
Search vendor "Tibco" for product "Foresight Archive And Retrieval System"
<= 5.1.0
Search vendor "Tibco" for product "Foresight Archive And Retrieval System" and version " <= 5.1.0"
healthcare
Affected
Tibco
Search vendor "Tibco"
Foresight Archive And Retrieval System
Search vendor "Tibco" for product "Foresight Archive And Retrieval System"
5.2.0
Search vendor "Tibco" for product "Foresight Archive And Retrieval System" and version "5.2.0"
healthcare
Affected
Tibco
Search vendor "Tibco"
Foresight Operational Monitor
Search vendor "Tibco" for product "Foresight Operational Monitor"
<= 5.1.0
Search vendor "Tibco" for product "Foresight Operational Monitor" and version " <= 5.1.0"
healthcare
Affected
Tibco
Search vendor "Tibco"
Foresight Operational Monitor
Search vendor "Tibco" for product "Foresight Operational Monitor"
5.2.0
Search vendor "Tibco" for product "Foresight Operational Monitor" and version "5.2.0"
healthcare
Affected
Tibco
Search vendor "Tibco"
Foresight Transaction Insight
Search vendor "Tibco" for product "Foresight Transaction Insight"
<= 5.1.0
Search vendor "Tibco" for product "Foresight Transaction Insight" and version " <= 5.1.0"
healthcare
Affected
Tibco
Search vendor "Tibco"
Foresight Transaction Insight
Search vendor "Tibco" for product "Foresight Transaction Insight"
5.2.0
Search vendor "Tibco" for product "Foresight Transaction Insight" and version "5.2.0"
healthcare
Affected