CVE-2018-12408: TIBCO ActiveMatrix BusinessWorks 5.X XML eXternal Entity Vulnerability
The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages, and may disclose the contents of files accessible to a running BusinessWorks engine Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks for z/Linux: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric: versions up to and including 5.13.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12408?
CVE-2018-12408 is rated as a medium severity vulnerability.
How do I fix CVE-2018-12408?
To mitigate CVE-2018-12408, users should upgrade to TIBCO ActiveMatrix BusinessWorks version 5.13.1 or later.
What type of vulnerability is CVE-2018-12408?
CVE-2018-12408 is an XML eXternal Entity (XXE) vulnerability.
Which software versions are affected by CVE-2018-12408?
CVE-2018-12408 affects TIBCO ActiveMatrix BusinessWorks and related products up to version 5.13.0.
What can an attacker do with CVE-2018-12408?
An attacker exploiting CVE-2018-12408 may be able to access sensitive data from the application.