CVE Published: 07/11/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2018 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO FTL - Community Edition Status : PUBLISHED
CVE-2018-12412 Description
The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO FTL - Community Edition: versions up to and including 5.4.0, TIBCO FTL - Developer Edition: versions up to and including 5.4.0, TIBCO FTL - Enterprise Edition: versions up to and including 5.4.0.
CWE-ID: CWE Name: The impact of this vulnerability includes the theoretical possibility that an attacker could gain full access to realm configuration. With such access, the attacker might also be able to gain access to all data sent to endpoints controlled by the realm server. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)