CVE-2020-27146: TIBCO iProcess Workspace Browser CSRF
The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27146?
CVE-2020-27146 has a medium severity rating, indicating a potential impact on the affected system.
How do I fix CVE-2020-27146?
To fix CVE-2020-27146, users should upgrade to a version of TIBCO iProcess Workspace (Browser) that is greater than 11.6.0.
Who is affected by CVE-2020-27146?
CVE-2020-27146 affects users of TIBCO iProcess Workspace (Browser) versions up to and including 11.6.0.
What type of vulnerability is CVE-2020-27146?
CVE-2020-27146 is a Cross Site Request Forgery (CSRF) vulnerability.
Can CVE-2020-27146 be exploited remotely?
Yes, CVE-2020-27146 can be exploited by an unauthenticated attacker with network access.