CVE Published: 12/01/2021 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO EBX Add-ons Status : PUBLISHED
CVE-2020-27148 Description
The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.\'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.\'s TIBCO EBX Add-ons: versions 4.4.2 and below.
Metrics
CVSS Version: 3.1 |
Base Score: 7.1 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
CWE-ID: CWE Name: The impact of these vulnerabilities include the possibility that an attacker would gain unauthorized read access to TIBCO EBX data, and the ability to cause a partial denial of service (partial DOS) on the affected system. Source: TIBCO Software Inc.
Common Attack Pattern Enumeration and Classification (CAPEC)