TIBCO Enterprise Message Service Vulnerable to CSRF Attacks
CVE-2018-12415
Key Information:
- Vendor
- Tibco
- Status
- Vendor
- CVE Published:
- 6 November 2018
Summary
The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Message Service: versions 8.4.0 and below, TIBCO Enterprise Message Service - Community Edition: versions 8.4.0 and below, and TIBCO Enterprise Message Service - Developer Edition: versions 8.4.0 and below.
Affected Version(s)
TIBCO Enterprise Message Service 8.4.0 and previous
TIBCO Enterprise Message Service - Community Edition 8.4.0 and previous
TIBCO Enterprise Message Service - Developer Edition 8.4.0 and previous
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved