SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:redhat:jboss_bpm_suite:6.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_bpm_suite:6.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_bpm_suite:6.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_bpm_suite:6.1.2:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_bpm_suite:6.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"last_affected": "6.0.0"
},
{
"introduced": "6.0.1"
},
{
"last_affected": "6.0.1"
},
{
"introduced": "6.0.3"
},
{
"last_affected": "6.0.3"
},
{
"introduced": "6.1"
},
{
"last_affected": "6.1"
},
{
"introduced": "6.1.2"
},
{
"last_affected": "6.1.2"
}
],
"vendor_product": "redhat:jboss_bpm_suite",
"source": "CPE_STRING"
},
{
"cpes": [
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:5.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:5.3.1:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.1:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "5.0.0"
},
{
"last_affected": "5.0.0"
},
{
"introduced": "5.3.1"
},
{
"last_affected": "5.3.1"
},
{
"introduced": "6.0.0"
},
{
"last_affected": "6.0.0"
},
{
"introduced": "6.0.1"
},
{
"last_affected": "6.0.1"
},
{
"introduced": "6.0.2"
},
{
"last_affected": "6.0.2"
},
{
"introduced": "6.0.3"
},
{
"last_affected": "6.0.3"
},
{
"introduced": "6.1"
},
{
"last_affected": "6.1"
},
{
"introduced": "6.3"
},
{
"last_affected": "6.3"
}
],
"vendor_product": "redhat:jboss_enterprise_brms_platform",
"source": "CPE_STRING"
}
]
}{
"cpe": "cpe:2.3:a:redhat:dashbuilder:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.5.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}[
{
"source": "https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"111647889128194931480811722479183416838",
"273985215608160427305160669618461684084",
"187139049491641220999445975182455683150",
"336640114799278420679753372525590489457"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2016-4999-5cda34e6",
"target": {
"file": "dashbuilder-backend/dashbuilder-dataset-sql/src/test/java/org/dashbuilder/dataprovider/sql/SQLTestSuite.java"
}
},
{
"source": "https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"105973552610407316146769326935849299456",
"114320129448123971438399054739505146646",
"148262174392690203089742235619161783127",
"219192059041892154837898543158867951865"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2016-4999-c57147bc",
"target": {
"file": "dashbuilder-backend/dashbuilder-dataset-sql/src/main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java"
}
},
{
"source": "https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "334569538173000158784445562462529603056",
"length": 61.0
},
"deprecated": false,
"id": "CVE-2016-4999-d9ee4bb4",
"target": {
"function": "getStringParameterSQL",
"file": "dashbuilder-backend/dashbuilder-dataset-sql/src/main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java"
}
},
{
"source": "https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b",
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "333188083673317335568536357355742992352",
"length": 298.0
},
"deprecated": false,
"id": "CVE-2016-4999-dc6ad52d",
"target": {
"function": "setUp",
"file": "dashbuilder-backend/dashbuilder-dataset-sql/src/test/java/org/dashbuilder/dataprovider/sql/SQLTestSuite.java"
}
}
]
"2026-07-08T12:41:40Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4999.json"