XML eXternal Entity Expansion Vulnerabilities with TIBCO Runtime Agent
CVE-2018-5434

5.8MEDIUM

Key Information:

Vendor
Tibco
Vendor
CVE Published:
13 June 2018

Summary

The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1.

Affected Version(s)

TIBCO Runtime Agent <= 5.10.0

TIBCO Runtime Agent for z/Linux <= 5.9.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

TIBCO would like to extend its appreciation to Baker Hamilton at Bishop Fox for discovery of this vulnerability.
.