【Vulnerability Alert】[TLP CLEAR] Interinfo|DreamMaker - SQL Injection
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026090803090404 | Publication Time | 2026-09-08 15:31:05 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-08 15:31:05 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】[TLP CLEAR] Interinfo|DreamMaker - SQL Injection |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000007 【Interinfo|DreamMaker - SQL Injection】(CVE-2026-85540, CVSS: 8.8) An authenticated remote attacker may inject arbitrary SQL commands to read, modify, and delete database contents. 【Interinfo|DreamMaker - Reflected Cross-site Scripting】(CVE-2026-85541, CVSS: 5.4) An authenticated remote attacker may use a malicious website to execute arbitrary JavaScript code in the user's browser. For detailed vulnerability information, please refer to "Vulnerability Information." Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
DreamMaker |
|||
|
[Recommended Actions] 【CVE-2026-85540】Use the SQLBuilder component. For self-developed functions involving database queries or data modifications, it is recommended to uniformly use the system's existing SQLBuilder component for SQL composition, parameter handling, and database operations. Directly concatenating external input data, form parameters, or URL parameters into SQL commands as strings should be avoided to reduce the risk of SQL Injection vulnerabilities caused by improper handling in self-developed programs. By using SQLBuilder or other standard components that support parameterized queries, input data processing and SQL execution security can be further strengthened, thereby reducing the possibility of applications being attacked through malicious SQL command injection. The relevant component development and usage manuals are available through the company's customer service system. 【CVE-2026-85541】 Solution 1: Restrict or disable baServer3. If the system has been updated to a version released after April 2026 and before June 2026, even if Java Composer 2.2 is still currently in use, access to jform and baServer3 can first be restricted through the WLIST whitelist mechanism (WhiteList) to prevent unauthorized users from directly accessing the relevant functions. Documentation for WLIST operations is available through the company's customer service system. If the current system does not require baServer3 for development, maintenance, or administrative purposes, servlet/baServer3.class may also be moved, disabled, or renamed directly. In principle, removing this component will not affect the normal operation of existing system applications, but the related management or development functions will no longer be available through this Servlet. Solution 2: Update to Java Composer Server 2.3. The current server-side Java Composer Server version and update date can be checked through the following URL, or determined from the information displayed when Java Composer starts: http://server-ip/servlet/baServer3
|
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





