CVE Published: 08/08/2019 |
CVE Updated: 17/09/2024 |
CVE Year: 2019 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO API Exchange Gateway Status : PUBLISHED
CVE-2019-11208 Description
The authorization component of TIBCO Software Inc.\'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint, when the implementation uses multiple scopes. This issue affects: TIBCO Software Inc.\'s TIBCO API Exchange Gateway version 2.3.1 and prior versions, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric version 2.3.1 and prior versions.
CWE-ID: CWE Name: The impact of this vulnerability includes the theoretical possibility that an attacker could gain access to all scopes defined for a given customer endpoint. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)