CVE Published: 13/06/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2018 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO Administrator - Enterprise Edition Status : PUBLISHED
CVE-2018-5432 Description
The TIBCO Administrator server component of of TIBCO Software Inc.\'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains multiple vulnerabilities wherein a malicious user could theoretically perform cross-site scripting (XSS) attacks by way of manipulating artifacts prior to uploading them. Affected releases are TIBCO Software Inc.\'s TIBCO Administrator - Enterprise Edition: versions up to and including 5.10.0, and TIBCO Administrator - Enterprise Edition for z/Linux: versions up to and including 5.9.1.
CWE-ID: CWE Name: The impact of the vulnerability includes the theoretical possibility of a user performing operations using another user
s access, including administrative functions being performed by a non-administrative user. The impact also theoretically includes access to all administrative information, including deployment variable settings ("global variables") Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)