TIBCO FTL Realm Server Vulnerable to CSRF Attacks
CVE-2018-12412
7.5HIGH
Key Information:
- Vendor
- Tibco
- Vendor
- CVE Published:
- 6 November 2018
Summary
The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO FTL - Community Edition: versions up to and including 5.4.0, TIBCO FTL - Developer Edition: versions up to and including 5.4.0, TIBCO FTL - Enterprise Edition: versions up to and including 5.4.0.
Affected Version(s)
TIBCO FTL - Community Edition <= 5.4.0
TIBCO FTL - Developer Edition <= 5.4.0
TIBCO FTL - Enterprise Edition <= 5.4.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved