CVE-2016-4999: SQL Injection
An SQL injection vulnerability was found in dashbuilder.
Original Jira: https://issues.jboss.org/browse/DASHBUILDE-113
Other sources
SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4999?
The severity of CVE-2016-4999 is classified as important.
How do I fix CVE-2016-4999?
To fix CVE-2016-4999, upgrade to the patched version of the affected software as recommended by the vendor.
Which software versions are affected by CVE-2016-4999?
CVE-2016-4999 affects Red Hat Dashbuilder and multiple versions of Red Hat JBoss BPM Suite and JBoss Enterprise BRMS Platform up to specified versions.
What type of vulnerability is CVE-2016-4999?
CVE-2016-4999 is an SQL injection vulnerability.
Is CVE-2016-4999 publicly known?
Yes, CVE-2016-4999 is a publicly disclosed vulnerability.