Executive brief
Borg SPM 2007, a legacy software product from BorG Technology Corporation, contains a critical security flaw that allows unauthorized individuals to access its database. An attacker can use this vulnerability to view, change, or delete sensitive business information without needing a username or password. Because this product reached its end-of-sale in 2008, organizations still using it are at significant risk of data theft or loss.
Technical details
A SQL injection vulnerability (CWE-89) exists in Borg SPM 2007 due to improper neutralization of special elements used in SQL commands. An unauthenticated remote attacker can exploit this flaw by sending specially crafted network requests to the application. Successful exploitation allows the attacker to execute arbitrary SQL commands against the backend database, providing full access to read, modify, or delete data. While the specific vulnerable component within the SPM 2007 suite is not named, the vendor recommends upgrading to SPM2025 SP1 or contacting them for patching assistance if under a maintenance contract.
Affected products
- BorG Technology Corporation Borg SPM 2007 2007 (Sales ended in 2008)
Timeline
- 2026-04-23: disclosed: Vulnerability disclosed by TWCERT/CC
- 2026-04-23: advisory: NVD published CVE-2026-6887