CVE-2017-5530
Summary
| CVE | CVE-2017-5530 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-12-13 02:29:00 UTC |
| Updated | 2019-10-09 23:28:00 UTC |
| Description | The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Community 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0, tibbr Enterprise 5.2.1 and below; 6.0.0; 6.0.1; 7.0.0. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Tibbr | 6.0.0 | All | All | All |
| Application | Tibco | Tibbr | 6.0.0 | All | All | All |
| Application | Tibco | Tibbr | 6.0.1 | All | All | All |
| Application | Tibco | Tibbr | 6.0.1 | All | All | All |
| Application | Tibco | Tibbr | 7.0.0 | All | All | All |
| Application | Tibco | Tibbr | 7.0.0 | All | All | All |
| Application | Tibco | Tibbr | 6.0.0 | All | All | All |
| Application | Tibco | Tibbr | 6.0.0 | All | All | All |
| Application | Tibco | Tibbr | 6.0.1 | All | All | All |
| Application | Tibco | Tibbr | 6.0.1 | All | All | All |
| Application | Tibco | Tibbr | 7.0.0 | All | All | All |
| Application | Tibco | Tibbr | 7.0.0 | All | All | All |
| Application | Tibco | Tibbr | All | All | All | All |
| Application | Tibco | Tibbr | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIBCO Security Advisory: December 12, 2017 - tibbr - 2017-5530 | TIBCO Software | CONFIRM | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.