CVE-2026-102616 risesoft-y9 WorkFlow-Engine SQL 注入漏洞
影响攻击者可远程注入 SQL 语句,读取或篡改数据库数据
risesoft-y9 WorkFlow-Engine 9.6.10 及之前版本中,CustomHistoricProcessServiceImpl.java 的 getByIdAndYear 方法对 year 与 processInstanceId 参数未做充分过滤,导致 SQL 注入。该漏洞位于 OAuth2 Resource Filter 组件,可远程利用,且利用代码已公开。厂商已提前被告知但未作回应。
影响范围
risesoft-y9 WorkFlow-Engine 9.6.10 及更早版本;具体受影响版本范围以厂商公告为准,暂无公开信息。
漏洞详情
漏洞类型为 SQL 注入。成因是 getByIdAndYear 方法在拼接 SQL 查询时直接使用外部传入的 year 和 processInstanceId 参数,未进行参数化处理或有效转义。攻击者可通过构造恶意参数在 SQL 语句的两个独立位置注入任意 SQL 片段,从而远程操纵数据库查询。
利用条件与风险
利用前提是攻击者能够访问相关接口并控制 year 或 processInstanceId 参数,无需认证或低权限即可触发。由于利用代码已公开,实战中被扫描和攻击的风险较高。
修复建议
官方尚未发布修复版本,建议关注厂商更新;临时缓解措施包括对相关接口进行访问控制、对输入参数做严格校验与参数化查询改造,或部署 WAF 拦截 SQL 注入攻击。
A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The sink is injectable on two independent positions, not just one. The vendor was contacted early about this disclosure but did not respond in any way.