First published: Tue Jun 12 2018(Updated: )
The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains multiple vulnerabilities wherein a malicious user could theoretically perform cross-site scripting (XSS) attacks by way of manipulating artifacts prior to uploading them. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions up to and including 5.10.0, and TIBCO Administrator - Enterprise Edition for z/Linux: versions up to and including 5.9.1.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tibco Administrator | <=5.9.1 | |
Tibco Administrator | <=5.10.0 |
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Administrator - Enterprise Edition versions 5.10.0 and below update to version 5.10.1 or higher TIBCO Administrator - Enterprise Edition for z/Linux versions 5.9.1 and below update to version 5.10.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5432 is a vulnerability in the TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition.
The severity of CVE-2018-5432 is high with a CVSS score of 5.4.
CVE-2018-5432 affects TIBCO Administrator - Enterprise Edition versions 5.9.1 and earlier, and versions 5.10.0 and earlier for z/Linux.
CVE-2018-5432 allows a malicious user to perform cross-site scripting (XSS) attacks.
To mitigate the risk of CVE-2018-5432, it is recommended to apply the necessary security patches provided by TIBCO Software Inc.