PT-2020-20646 · Tibco · Tibco Foresight Transaction Insight Healthcare Edition+5

Published

2020-10-20

·

Updated

2020-10-30

·

CVE-2020-9417

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TIBCO Foresight Archive and Retrieval System versions 5.1.0 and below, version 5.2.0 TIBCO Foresight Archive and Retrieval System Healthcare Edition versions 5.1.0 and below, version 5.2.0 TIBCO Foresight Operational Monitor versions 5.1.0 and below, version 5.2.0 TIBCO Foresight Operational Monitor Healthcare Edition versions 5.1.0 and below, version 5.2.0 TIBCO Foresight Transaction Insight versions 5.1.0 and below, version 5.2.0 TIBCO Foresight Transaction Insight Healthcare Edition versions 5.1.0 and below, version 5.2.0
Description The Transaction Insight reporting component contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection.
Recommendations For TIBCO Foresight Archive and Retrieval System versions 5.1.0 and below, version 5.2.0, update to a version that includes the fix for this issue. For TIBCO Foresight Archive and Retrieval System Healthcare Edition versions 5.1.0 and below, version 5.2.0, update to a version that includes the fix for this issue. For TIBCO Foresight Operational Monitor versions 5.1.0 and below, version 5.2.0, update to a version that includes the fix for this issue. For TIBCO Foresight Operational Monitor Healthcare Edition versions 5.1.0 and below, version 5.2.0, update to a version that includes the fix for this issue. For TIBCO Foresight Transaction Insight versions 5.1.0 and below, version 5.2.0, update to a version that includes the fix for this issue. For TIBCO Foresight Transaction Insight Healthcare Edition versions 5.1.0 and below, version 5.2.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Transaction Insight reporting component to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9417

Affected Products

Tibco Foresight Archive/Retrieval System
Tibco Foresight Archive/Retrieval System Healthcare Edition
Tibco Foresight Operational Monitor
Tibco Foresight Operational Monitor Healthcare Edition
Tibco Foresight Transaction Insight
Tibco Foresight Transaction Insight Healthcare Edition