Impact
Tanium Asset contains a SQL injection vulnerability classified as CWE‑89. The CVE description states only that a SQL injection flaw exists; no explicit impact details are provided. By definition, such a flaw could allow unauthorized manipulation or disclosure of data stored in the underlying database.
Affected Systems
The affected product is Tanium Asset. No specific version information is included in the advisory, so any installation of Tanium Asset that has not applied the vendor’s update could be vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity rating. The EPSS score of less than 1% suggests a low likelihood of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed active exploits. The likely attack vector is inferred to be remote via a web interface or API that accepts user-controlled input, based on the nature of SQL injection vulnerabilities and the typical operation of Tanium Asset.
OpenCVE Enrichment