CVE-2018-12415: TIBCO Enterprise Message Service Vulnerable to CSRF Attacks
The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Message Service: versions 8.4.0 and below, TIBCO Enterprise Message Service - Community Edition: versions 8.4.0 and below, and TIBCO Enterprise Message Service - Developer Edition: versions 8.4.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12415?
CVE-2018-12415 has been rated as a medium severity vulnerability.
How do I fix CVE-2018-12415?
To fix CVE-2018-12415, you should upgrade TIBCO Enterprise Message Service to version 8.4.1 or later.
What systems are affected by CVE-2018-12415?
CVE-2018-12415 affects TIBCO Enterprise Message Service versions up to and including 8.4.0.
What type of vulnerability is CVE-2018-12415?
CVE-2018-12415 is classified as a security vulnerability in the Central Administration server component of TIBCO Software.
Can CVE-2018-12415 be exploited remotely?
Yes, CVE-2018-12415 can potentially be exploited remotely by an attacker.