« Volver al listado

CVE-2020-9417

Estado: ModificadaAlta (8.8)—

The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection.

Leer descripción completaMostrar menos

Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-9417",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@tibco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@tibco.com",
      "affectedData": [
        {
          "vendor": "TIBCO Software Inc.",
          "product": "TIBCO Foresight Archive and Retrieval System",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "5.1.0"
            },
            {
              "status": "affected",
              "version": "5.2.0"
            }
          ]
        },
        {
          "vendor": "TIBCO Software Inc.",
          "product": "TIBCO Foresight Archive and Retrieval System Healthcare Edition",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "5.1.0"
            },
            {
              "status": "affected",
              "version": "5.2.0"
            }
          ]
        },
        {
          "vendor": "TIBCO Software Inc.",
          "product": "TIBCO Foresight Operational Monitor",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "5.1.0"
            },
            {
              "status": "affected",
              "version": "5.2.0"
            }
          ]
        },
        {
          "vendor": "TIBCO Software Inc.",
          "product": "TIBCO Foresight Operational Monitor Healthcare Edition",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "5.1.0"
            },
            {
              "status": "affected",
              "version": "5.2.0"
            }
          ]
        },
        {
          "vendor": "TIBCO Software Inc.",
          "product": "TIBCO Foresight Transaction Insight",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "5.1.0"
            },
            {
              "status": "affected",
              "version": "5.2.0"
            }
          ]
        },
        {
          "vendor": "TIBCO Software Inc.",
          "product": "TIBCO Foresight Transaction Insight Healthcare Edition",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "5.1.0"
            },
            {
              "status": "affected",
              "version": "5.2.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-20T21:15:13.023",
  "references": [
    {
      "url": "http://www.tibco.com/services/support/advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@tibco.com"
    },
    {
      "url": "http://www.tibco.com/services/support/advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0."
    },
    {
      "lang": "es",
      "value": "El componente de reporte Transaction Insight de TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight y TIBCO Foresight Transaction Insight Healthcare Edition, de TIBCO Software Inc, contiene una vulnerabilidad que teóricamente permite a un atacante autenticado llevar a cabo una inyección SQL. Las versiones afectadas son TIBCO Foresight Archive and Retrieval System de TIBCO Software Inc.: versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Operational Monitor : versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versiones 5.1.0 y posteriores, versión 5.2.0, TIBCO Foresight Transaction Insight: versiones 5.1.0 y anteriores, versión 5.2.0, y TIBCO Foresight Transaction Insight Healthcare Edition: versiones 5.1.0 y anteriores, versión 5.2.0"
    }
  ],
  "lastModified": "2026-06-17T03:27:54.847",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24CC381C-70BA-46B0-A8C6-9DD7B0932085",
              "versionEndIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:5.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12FFB778-2E31-4E75-99B3-AB620193B2A4"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CB54518-7889-447B-B8EC-812FF011C596",
              "versionEndIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:5.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE96EB6F-2050-4876-8466-15F0EA0079AA"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F6A4872-40D9-4E99-B6CE-11767905CAC1",
              "versionEndIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:5.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C48D320-634F-4351-920D-03A94F818685"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:*:*:*:*:healthcare:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0CA39E8-468D-41B5-8DF2-BEEAFECFB064",
              "versionEndIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:5.2.0:*:*:*:healthcare:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "197E69E9-1896-4B54-A06A-EFDC25E2100D"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:*:*:*:*:healthcare:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B035336-4C16-4992-B141-73FE1E921E62",
              "versionEndIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:5.2.0:*:*:*:healthcare:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DC4D6EA-D63C-4377-8C90-44B0E1F32B21"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:*:*:*:*:healthcare:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D353B558-A623-45C9-91DC-E899034B0D69",
              "versionEndIncluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:5.2.0:*:*:*:healthcare:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D339F196-1147-4F16-A137-67C02D910850"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@tibco.com"
}