First published: Wed Jun 20 2018(Updated: )
The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data Virtualization: 7.0.5; 7.0.6.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Data Virtualization | =7.0.5 | |
TIBCO Data Virtualization | =7.0.6 |
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: * TIBCO Data Virtualization versions 7.0.5 and 7.0.6 update to version 7.0.7 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5428 is a vulnerability in the version control adapters component of TIBCO Data Virtualization that allows for arbitrary command execution.
The severity of CVE-2018-5428 is critical with a CVSS score of 8.8.
TIBCO Data Virtualization versions 7.0.5 and 7.0.6 are affected by CVE-2018-5428.
To fix CVE-2018-5428, it is recommended to update TIBCO Data Virtualization to a version that is not affected by the vulnerability.
More information about CVE-2018-5428 can be found at the following references: - [http://www.securityfocus.com/bid/104518](http://www.securityfocus.com/bid/104518) - [https://www.tibco.com/support/advisories/2018/06/tibco-security-advisory-june-20-2018-tibco-data-virtualization](https://www.tibco.com/support/advisories/2018/06/tibco-security-advisory-june-20-2018-tibco-data-virtualization)