Impact
The vulnerability is a classic SQL injection flaw located in Tanium's Patch component. Attackers that can manipulate input accepted by the Patch module may read or modify database contents, leading to unauthorized data disclosure or tampering. The flaw is classified as CWE‑89, indicating that unsanitized input can reach SQL statements.
Affected Systems
Affected only the Tanium Patch product, with no specific version details provided. Administrators should review which instances of Tanium Patch they are running and verify if the vulnerability applies.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is less than 1%, meaning the likelihood of observed exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly documented, but given the nature of the flaw it is inferred that the exploit would originate from interactions with the Patch subsystem, such as via the Patch API or a management console that can inject SQL.
OpenCVE Enrichment