CVE-2017-5535
Summary
| CVE | CVE-2017-5535 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-01 18:29:00 UTC |
| Updated | 2019-10-09 23:28:00 UTC |
| Description | The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encryption mechanisms and the use of weak ciphers. A malicious actor could theoretically compromise the traffic between any of the components. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0. |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Datasynapse Gridserver Manager | 6.0.0 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.0.1 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.0.2 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.1.0 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.1.1 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.2.0 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.0.0 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.0.1 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.0.2 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.1.0 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.1.1 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | 6.2.0 | All | All | All |
| Application | Tibco | Datasynapse Gridserver Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIBCO Security Advisory: May 1, 2018 - TIBCO DataSynapse GridServer - 2017-5535 | TIBCO Software | CONFIRM | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.