CVE-2017-5530 Vulnerability Details

  /     /     /  

CVE-2017-5530 Metadata Quick Info

CVE Published: 13/12/2017 | CVE Updated: 16/09/2024 | CVE Year: 2017
Source: tibco | Vendor: TIBCO Software Inc. | Product: tibbr Community
Status : PUBLISHED

CVE-2017-5530 Description

The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: The impact of this vulnerability includes, for already authorized users, the theoretical escalation of privileges to those of any other user.
Source: TIBCO Software Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).