VDB

CVE-2016-4999

CVE-2016-4999 PUBLISHED CVSS 9.800000190734863 CRITICAL

SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

EPSS 3.65% · 88.5th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.65%
88.5th percentile

Affected Products

VendorProductVersions
n/an/a*
redhatjboss_bpm_suite6.0.1, 6.0.3, 6.0.0
redhatdashbuilder0
redhatjboss_enterprise_brms_platform6.0.0, 5.3.1, 5.0.0

Timeline

  • Aug 5, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 7, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›