The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-30237 The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight, and TIBCO Foresight Transaction Insight Healthcare Edition contains a vulnerability that theoretically allows an authenticated attacker to perform SQL injection. Affected releases are TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Archive and Retrieval System Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Operational Monitor Healthcare Edition: versions 5.1.0 and below, version 5.2.0, TIBCO Foresight Transaction Insight: versions 5.1.0 and below, version 5.2.0, and TIBCO Foresight Transaction Insight Healthcare Edition: versions 5.1.0 and below, version 5.2.0.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO Foresight Archive and Retrieval System versions 5.1.0 and below update to version 5.1.1 or higher TIBCO Foresight Archive and Retrieval System version 5.2.0 update to version 5.2.1 or higher TIBCO Foresight Archive and Retrieval System Healthcare Edition versions 5.1.0 and below update to version 5.1.1 or higher TIBCO Foresight Archive and Retrieval System Healthcare Edition version 5.2.0 update to version 5.2.1 or higher TIBCO Foresight Operational Monitor versions 5.1.0 and below update to version 5.1.1 or higher TIBCO Foresight Operational Monitor version 5.2.0 update to version 5.2.1 or higher TIBCO Foresight Operational Monitor Healthcare Edition versions 5.1.0 and below update to version 5.1.1 or higher TIBCO Foresight Operational Monitor Healthcare Edition version 5.2.0 update to version 5.2.1 or higher TIBCO Foresight Transaction Insight versions 5.1.0 and below update to version 5.1.1 or higher TIBCO Foresight Transaction Insight version 5.2.0 update to version 5.2.1 or higher TIBCO Foresight Transaction Insight Healthcare Edition versions 5.1.0 and below update to version 5.1.1 or higher TIBCO Foresight Transaction Insight Healthcare Edition version 5.2.0 update to version 5.2.1 or higher


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-17T03:02:27.461Z

Reserved: 2020-02-26T00:00:00

Link: CVE-2020-9417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-20T21:15:13.023

Modified: 2024-11-21T05:40:36.043

Link: CVE-2020-9417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.