CVE Published: 26/03/2019 |
CVE Updated: 17/09/2024 |
CVE Year: 2019 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO Data Science for AWS Status : PUBLISHED
CVE-2019-8988 Description
The application server component of TIBCO Software Inc.\'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site contains a vulnerability that theoretically allows a user to escalate their privileges on the affected system, in a way that may allow for data modifications and deletions that should be denied. Affected releases are TIBCO Software Inc.\'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.
CWE-ID: CWE Name: The impact of this vulnerability includes the theoretical possibility that a malicious actor could modify or delete data on the system that they should not be able to change, affecting the output that others might see. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)