CVE-2020-9417

HIGH

TIBCO Foresight Transaction Insight Reporting Component <= 5.1.0 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.tibco.com/services/support/advisories

Scores

CVSS v3 7.6
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

Details

CWE
CWE-89
Status published
Products (6)
tibco/foresight_archive_and_retrieval_system 5.2.0 (2 CPE variants)
tibco/foresight_archive_and_retrieval_system < 5.1.0 (2 CPE variants)
tibco/foresight_operational_monitor 5.2.0 (2 CPE variants)
tibco/foresight_operational_monitor < 5.1.0 (2 CPE variants)
tibco/foresight_transaction_insight 5.2.0 (2 CPE variants)
tibco/foresight_transaction_insight < 5.1.0 (2 CPE variants)
Published Oct 20, 2020
Tracked Since Feb 18, 2026