First published: Wed Jun 13 2018(Updated: )
The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1.
Credit: security@tibco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tibco Runtime Agent | <=5.9.1 | |
Tibco Runtime Agent | <=5.10.0 |
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Runtime Agent versions 5.10.0 and below update to version 5.10.1 or higher TIBCO Runtime Agent for z/Linux versions 5.9.1 and below update to version 5.10.1 or higher
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5434 is a vulnerability in the TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent and TIBCO Runtime Agent for z/Linux, which allows for XML external entity expansion (XXE) attacks to disclose host machine information.
CVE-2018-5434 has a severity rating of 6.5 out of 10, making it a medium severity vulnerability.
TIBCO Software Inc.'s Tibco Runtime Agent versions up to 5.9.1 and 5.10.0 are affected by CVE-2018-5434.
CVE-2018-5434 is associated with CWE-611, which relates to XML external entity (XXE) processing vulnerabilities.
To mitigate CVE-2018-5434, it is recommended to apply the necessary patches or updates provided by TIBCO Software Inc. and follow their security advisories.