CVE-2020-9417
The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection.
Leer descripción completaMostrar menos
Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.87%
- Percentil entre todas las CVEs puntuadas: 57
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-9417",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@tibco.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@tibco.com",
"affectedData": [
{
"vendor": "TIBCO Software Inc.",
"product": "TIBCO Foresight Archive and Retrieval System",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "5.1.0"
},
{
"status": "affected",
"version": "5.2.0"
}
]
},
{
"vendor": "TIBCO Software Inc.",
"product": "TIBCO Foresight Archive and Retrieval System Healthcare Edition",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "5.1.0"
},
{
"status": "affected",
"version": "5.2.0"
}
]
},
{
"vendor": "TIBCO Software Inc.",
"product": "TIBCO Foresight Operational Monitor",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "5.1.0"
},
{
"status": "affected",
"version": "5.2.0"
}
]
},
{
"vendor": "TIBCO Software Inc.",
"product": "TIBCO Foresight Operational Monitor Healthcare Edition",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "5.1.0"
},
{
"status": "affected",
"version": "5.2.0"
}
]
},
{
"vendor": "TIBCO Software Inc.",
"product": "TIBCO Foresight Transaction Insight",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "5.1.0"
},
{
"status": "affected",
"version": "5.2.0"
}
]
},
{
"vendor": "TIBCO Software Inc.",
"product": "TIBCO Foresight Transaction Insight Healthcare Edition",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "5.1.0"
},
{
"status": "affected",
"version": "5.2.0"
}
]
}
]
}
],
"published": "2020-10-20T21:15:13.023",
"references": [
{
"url": "http://www.tibco.com/services/support/advisories",
"tags": [
"Vendor Advisory"
],
"source": "security@tibco.com"
},
{
"url": "http://www.tibco.com/services/support/advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0."
},
{
"lang": "es",
"value": "El componente de reporte Transaction Insight de TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight y TIBCO Foresight Transaction Insight Healthcare Edition, de TIBCO Software Inc, contiene una vulnerabilidad que teóricamente permite a un atacante autenticado llevar a cabo una inyección SQL. Las versiones afectadas son TIBCO Foresight Archive and Retrieval System de TIBCO Software Inc.: versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Operational Monitor : versiones 5.1.0 y anteriores, versión 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versiones 5.1.0 y posteriores, versión 5.2.0, TIBCO Foresight Transaction Insight: versiones 5.1.0 y anteriores, versión 5.2.0, y TIBCO Foresight Transaction Insight Healthcare Edition: versiones 5.1.0 y anteriores, versión 5.2.0"
}
],
"lastModified": "2026-06-17T03:27:54.847",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24CC381C-70BA-46B0-A8C6-9DD7B0932085",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:5.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12FFB778-2E31-4E75-99B3-AB620193B2A4"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CB54518-7889-447B-B8EC-812FF011C596",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:5.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE96EB6F-2050-4876-8466-15F0EA0079AA"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F6A4872-40D9-4E99-B6CE-11767905CAC1",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:5.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C48D320-634F-4351-920D-03A94F818685"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:*:*:*:*:healthcare:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0CA39E8-468D-41B5-8DF2-BEEAFECFB064",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_archive_and_retrieval_system:5.2.0:*:*:*:healthcare:*:*:*",
"vulnerable": true,
"matchCriteriaId": "197E69E9-1896-4B54-A06A-EFDC25E2100D"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:*:*:*:*:healthcare:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B035336-4C16-4992-B141-73FE1E921E62",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_operational_monitor:5.2.0:*:*:*:healthcare:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DC4D6EA-D63C-4377-8C90-44B0E1F32B21"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:*:*:*:*:healthcare:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D353B558-A623-45C9-91DC-E899034B0D69",
"versionEndIncluding": "5.1.0"
},
{
"criteria": "cpe:2.3:a:tibco:foresight_transaction_insight:5.2.0:*:*:*:healthcare:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D339F196-1147-4F16-A137-67C02D910850"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@tibco.com"
}