TIBCO Enterprise Message Service Vulnerable to CSRF Attacks
CVE-2018-12415
Summary
The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Message Service: versions 8.4.0 and below, TIBCO Enterprise Message Service - Community Edition: versions 8.4.0 and below, and TIBCO Enterprise Message Service - Developer Edition: versions 8.4.0 and below.
Affected Version(s)
TIBCO Enterprise Message Service 8.4.0 and previous
TIBCO Enterprise Message Service - Community Edition 8.4.0 and previous
TIBCO Enterprise Message Service - Developer Edition 8.4.0 and previous
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved