CVE Published: 13/12/2017 |
CVE Updated: 16/09/2024 |
CVE Year: 2017 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: tibbr Community Status : PUBLISHED
CVE-2017-5530 Description
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0.
CWE-ID: CWE Name: The impact of this vulnerability includes, for already authorized users, the theoretical escalation of privileges to those of any other user. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)