Executive brief
EFence is a database security product developed by Thinking Software Technology. It contains a SQL injection vulnerability that allows unauthenticated attackers on the network to inject malicious SQL commands and read sensitive data stored in the database, potentially exposing confidential business information.
Technical details
EFence versions 1.2.65 DB Ver:55 and earlier contain a SQL injection vulnerability in an unauthenticated network-accessible component. The vulnerability allows remote attackers without credentials to inject arbitrary SQL commands to read database contents. No authentication is required and the attack is network-reachable with low complexity. The vulnerability impacts confidentiality by enabling unauthorized data access. A fix is available in version 1.2.67 DB Ver:57 and later.
Affected products
- Thinking Software Technology EFence 1.2.65 DB Ver:55 and earlier
Timeline
- 2026-09-14: disclosed