Back to overview

CVE-2019-11210

CRITICAL
10.0
CVSS 3.0
Description
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.

Metadata

CVE ID
CVE-2019-11210
State
PUBLISHED
Assigner
tibco
Reserved
2019-04-12 00:00 UTC
Published
2019-09-18 22:20 UTC
Last updated
2024-09-16 19:20 UTC
Vendor / Product
TIBCO Software Inc. / TIBCO Enterprise Runtime for R - Server Edition
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
TIBCO Software Inc. TIBCO Enterprise Runtime for R - Server Edition 1.2.0 and below
TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0, 10.5.0
Weakness (CWE)
CWESourceDescription
cna The impact of this vulnerability includes the theoretical possibility that an attacker could gain full control of the operating system account hosting the affected component. In addition to the information flowing through the system, the exposed information might include secrets necessary to issue trusted requests to other TIBCO Spotfire servers.
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview