CVE-2019-11210: TIBCO Enterprise Runtime for R Server Exposes Remote Code Execution
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-11210?
CVE-2019-11210 is a vulnerability in TIBCO Enterprise Runtime for R - Server Edition and TIBCO Spotfire Analytics Platform.
What is the severity of CVE-2019-11210?
CVE-2019-11210 has a severity rating of critical.
How can an unauthenticated user exploit CVE-2019-11210?
An unauthenticated user can exploit CVE-2019-11210 to bypass access controls and remotely execute code.
Which versions of TIBCO Enterprise Runtime for R are affected by CVE-2019-11210?
CVE-2019-11210 affects TIBCO Enterprise Runtime for R 1.2.0.
Which versions of TIBCO Spotfire Analytics Platform for AWS are affected by CVE-2019-11210?
CVE-2019-11210 affects TIBCO Spotfire Analytics Platform for AWS 10.4.0 and 10.5.0.
How do I fix CVE-2019-11210?
To fix CVE-2019-11210, users should apply the necessary security patches provided by TIBCO Software Inc.