{"id":"CVE-2016-4999","details":"SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.","modified":"2026-07-08T12:41:40.083130Z","published":"2016-08-05T15:59:06.987Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:redhat:jboss_bpm_suite:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_bpm_suite:6.0.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_bpm_suite:6.0.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_bpm_suite:6.1.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_bpm_suite:6.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0.0"},{"last_affected":"6.0.0"},{"introduced":"6.0.1"},{"last_affected":"6.0.1"},{"introduced":"6.0.3"},{"last_affected":"6.0.3"},{"introduced":"6.1"},{"last_affected":"6.1"},{"introduced":"6.1.2"},{"last_affected":"6.1.2"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_bpm_suite"},{"cpes":["cpe:2.3:a:redhat:jboss_enterprise_brms_platform:5.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:5.3.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.0.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_brms_platform:6.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.0.0"},{"last_affected":"5.0.0"},{"introduced":"5.3.1"},{"last_affected":"5.3.1"},{"introduced":"6.0.0"},{"last_affected":"6.0.0"},{"introduced":"6.0.1"},{"last_affected":"6.0.1"},{"introduced":"6.0.2"},{"last_affected":"6.0.2"},{"introduced":"6.0.3"},{"last_affected":"6.0.3"},{"introduced":"6.1"},{"last_affected":"6.1"},{"introduced":"6.3"},{"last_affected":"6.3"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_enterprise_brms_platform"}]},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91795"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:1428"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:1429"},{"type":"ADVISORY","url":"https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1349990"},{"type":"REPORT","url":"https://issues.jboss.org/browse/DASHBUILDE-113"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dashbuilder/dashbuilder","events":[{"introduced":"0"},{"last_affected":"0eecbbbf717ec2eda81d5a408f94e3b4c023197f"},{"fixed":"8574899e3b6455547b534f570b2330ff772e524b"}],"database_specific":{"cpe":"cpe:2.3:a:redhat:dashbuilder:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.5.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.5.0.Final"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4999.json","vanir_signatures_modified":"2026-07-08T12:41:40Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b","target":{"file":"dashbuilder-backend/dashbuilder-dataset-sql/src/test/java/org/dashbuilder/dataprovider/sql/SQLTestSuite.java"},"deprecated":false,"digest":{"line_hashes":["111647889128194931480811722479183416838","273985215608160427305160669618461684084","187139049491641220999445975182455683150","336640114799278420679753372525590489457"],"threshold":0.9},"id":"CVE-2016-4999-5cda34e6"},{"deprecated":false,"digest":{"line_hashes":["105973552610407316146769326935849299456","114320129448123971438399054739505146646","148262174392690203089742235619161783127","219192059041892154837898543158867951865"],"threshold":0.9},"id":"CVE-2016-4999-c57147bc","signature_type":"Line","signature_version":"v1","source":"https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b","target":{"file":"dashbuilder-backend/dashbuilder-dataset-sql/src/main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java"}},{"target":{"file":"dashbuilder-backend/dashbuilder-dataset-sql/src/main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java","function":"getStringParameterSQL"},"deprecated":false,"digest":{"function_hash":"334569538173000158784445562462529603056","length":61},"id":"CVE-2016-4999-d9ee4bb4","signature_type":"Function","signature_version":"v1","source":"https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b"},{"signature_version":"v1","source":"https://github.com/dashbuilder/dashbuilder/commit/8574899e3b6455547b534f570b2330ff772e524b","target":{"file":"dashbuilder-backend/dashbuilder-dataset-sql/src/test/java/org/dashbuilder/dataprovider/sql/SQLTestSuite.java","function":"setUp"},"deprecated":false,"digest":{"function_hash":"333188083673317335568536357355742992352","length":298},"id":"CVE-2016-4999-dc6ad52d","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}