Impact
A classic SQL injection flaw exists in Tanium Threat Response, allowing the execution of arbitrary SQL statements through unsanitized input. The impact is primarily unauthorized data access or modification, and it could potentially lead to privilege escalation if the database user has elevated rights. This vulnerability is a classic instance of CWE-89.
Affected Systems
The flaw affects Tanium Threat Response. No specific version information is provided in the advisory, so the vulnerability may exist in all variants of the product until patches are applied.
Risk and Exploitability
The CVSS score of 8.8 highlights a high severity level, while the EPSS score below 1% indicates a low current exploitation probability but does not eliminate risk. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to be through authenticated API or UI interactions that accept unsafe parameters, enabling an attacker to inject malicious SQL commands.
OpenCVE Enrichment