Back to overview

CVE-2019-11211

CRITICAL
9.9
CVSS 3.0
Description
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.

Metadata

CVE ID
CVE-2019-11211
State
PUBLISHED
Assigner
tibco
Reserved
2019-04-12 00:00 UTC
Published
2019-09-18 22:21 UTC
Last updated
2024-09-17 03:34 UTC
Vendor / Product
TIBCO Software Inc. / TIBCO Enterprise Runtime for R - Server Edition
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
TIBCO Software Inc. TIBCO Enterprise Runtime for R - Server Edition 1.2.0 and below
TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0, 10.5.0
Weakness (CWE)
CWESourceDescription
cna The impact of this vulnerability includes the theoretical possibility that an attacker could gain full control of the operating system account hosting the affected component. In addition to the information flowing through the system, the exposed information might include secrets necessary to issue trusted requests to other TIBCO Spotfire servers.
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview