CVE-2018-5434: XML eXternal Entity Expansion Vulnerabilities with TIBCO Runtime Agent
The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TIBCO Runtime Agent for z/Linuxto a version that resolves this vulnerability.Fixed in 5.10.1 - Upgrade
Upgrade
TIBCO Runtime Agentto a version that resolves this vulnerability.Fixed in 5.10.1
Event History
Frequently Asked Questions
What is CVE-2018-5434?
CVE-2018-5434 is a vulnerability in the TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent and TIBCO Runtime Agent for z/Linux, which allows for XML external entity expansion (XXE) attacks to disclose host machine information.
How severe is CVE-2018-5434?
CVE-2018-5434 has a severity rating of 6.5 out of 10, making it a medium severity vulnerability.
What software is affected by CVE-2018-5434?
TIBCO Software Inc.'s Tibco Runtime Agent versions up to 5.9.1 and 5.10.0 are affected by CVE-2018-5434.
What is the CWE of CVE-2018-5434?
CVE-2018-5434 is associated with CWE-611, which relates to XML external entity (XXE) processing vulnerabilities.
How can I mitigate CVE-2018-5434?
To mitigate CVE-2018-5434, it is recommended to apply the necessary patches or updates provided by TIBCO Software Inc. and follow their security advisories.