Impact
The vulnerability in Tanium Comply allows an attacker to inject arbitrary SQL statements into database queries because input is not properly validated or parameterized. This weakness is classified as CWE-89 and could enable attackers to read, modify, or delete sensitive data stored in the Comply database, potentially leading to a data breach or disruption of services.
Affected Systems
Affected systems are Tanium Comply installations. No specific product versions are listed in the advisory, so any deployment of Tanium Comply is potentially vulnerable unless more recent releases are confirmed to include the fix.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity, while the EPSS score is not available, so the current guess on exploitation likelihood is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the exposed web or API interface that accepts unfiltered input; thus remote attackers could exploit the flaw without local privileges, although exact prerequisites are not detailed in the advisory.
OpenCVE Enrichment