CVE-2018-5432: TIBCO Administrator - Enterprise Edition Cross-Site Scripting Vulnerability
The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains multiple vulnerabilities wherein a malicious user could theoretically perform cross-site scripting (XSS) attacks by way of manipulating artifacts prior to uploading them. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions up to and including 5.10.0, and TIBCO Administrator - Enterprise Edition for z/Linux: versions up to and including 5.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TIBCO Administrator - Enterprise Editionto a version that resolves this vulnerability.Fixed in 5.10.1 or higher - Upgrade
Upgrade
TIBCO Administrator - Enterprise Edition for z/Linuxto a version that resolves this vulnerability.Fixed in 5.10.1 or higher
Event History
Frequently Asked Questions
What is CVE-2018-5432?
CVE-2018-5432 is a vulnerability in the TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition.
What is the severity of CVE-2018-5432?
The severity of CVE-2018-5432 is high with a CVSS score of 5.4.
How does CVE-2018-5432 affect TIBCO Administrator?
CVE-2018-5432 affects TIBCO Administrator - Enterprise Edition versions 5.9.1 and earlier, and versions 5.10.0 and earlier for z/Linux.
What is the impact of CVE-2018-5432?
CVE-2018-5432 allows a malicious user to perform cross-site scripting (XSS) attacks.
How can I mitigate the risk of CVE-2018-5432?
To mitigate the risk of CVE-2018-5432, it is recommended to apply the necessary security patches provided by TIBCO Software Inc.