SAML protocol handling errors in tibbr
CVE-2017-5530
8.1HIGH
Key Information:
- Vendor
- Tibco
- Vendor
- CVE Published:
- 13 December 2017
Summary
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0.
Affected Version(s)
tibbr Community 5.2.1 and below
tibbr Community 6.0.0
tibbr Community 6.0.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved