First published: Wed Jun 13 2018(Updated: )
The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions up to and including 5.10.0, and TIBCO Administrator - Enterprise Edition for z/Linux: versions up to and including 5.9.1.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tibco Administrator | <=5.9.1 | |
Tibco Administrator | <=5.10.0 |
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Administrator - Enterprise Edition versions 5.10.0 and below update to version 5.10.1 or higher TIBCO Administrator - Enterprise Edition for z/Linux versions 5.9.1 and below update to version 5.10.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5433 is a vulnerability in TIBCO Administrator server component that allows XML external entity expansion (XXE) attacks.
CVE-2018-5433 affects TIBCO Administrator - Enterprise Edition and TIBCO Administrator - Enterprise Edition for z/Linux.
The severity of CVE-2018-5433 is medium with a CVSS score of 6.5.
A malicious user can exploit CVE-2018-5433 by performing XML external entity expansion (XXE) attacks to disclose host machine information.
You can find more information about CVE-2018-5433 at the following references: [1] http://www.securityfocus.com/bid/104451 [2] https://www.tibco.com/support/advisories/2018/06/security-advisory-june-12-2018-tibco-administrator-enterprise-edition-2018-5433