Impact
A classic SQL injection flaw exists in Tenable Security Center, enabling an attacker to inject arbitrary SQL commands into the application’s input fields. With this vulnerability an attacker could retrieve sensitive information stored in the backend database that the application must not reveal, leading to a loss of confidentiality. The likelihood that the flaw can be used to exfiltrate data is inferred by the description’s mention of unauthorized database access.
Affected Systems
The product affected is Tenable Security Center. Any deployment that does not include the vendor‑supplied fix released as version 6.9.0 is considered vulnerable; no further version details are provided in the public advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send specially crafted input to a susceptible web interface of Security Center; authentication requirements are not specified, so the real risk depends on the system’s existing access controls. The primary impact is confidentiality loss, as exposed data can be read by an attacker.
OpenCVE Enrichment