XML eXternal Entity Expansion Vulnerabilities with TIBCO Runtime Agent
CVE-2018-5434
5.8MEDIUM
Summary
The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1.
Affected Version(s)
TIBCO Runtime Agent <= 5.10.0
TIBCO Runtime Agent for z/Linux <= 5.9.1
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
TIBCO would like to extend its appreciation to Baker Hamilton at Bishop Fox for discovery of this vulnerability.