CVE-2018-12414
Summary
| CVE | CVE-2018-12414 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-06 23:29:00 UTC |
| Updated | 2019-10-09 23:33:00 UTC |
| Description | The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), and Rendezvous Daemon Manager (rvdm) components of TIBCO Software Inc.'s TIBCO Rendezvous, TIBCO Rendezvous Developer Edition, TIBCO Rendezvous for z/Linux, TIBCO Rendezvous for z/OS, TIBCO Rendezvous Network Server, TIBCO Substation ES contain vulnerabilities which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Rendezvous: versions up to and including 8.4.5, TIBCO Rendezvous Developer Edition: versions up to and including 8.4.5, TIBCO Rendezvous for z/Linux: versions up to and including 8.4.5, TIBCO Rendezvous for z/OS: versions up to and including 8.4.5, TIBCO Rendezvous Network Server: versions up to and including 1.1.2, and TIBCO Substation ES: versions up to and including 2.12.2. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Rendezvous | All | All | All | All |
| Application | Tibco | Rendezvous | All | All | All | All |
| Application | Tibco | Rendezvous For Z/linux | All | All | All | All |
| Application | Tibco | Rendezvous For Z/os | All | All | All | All |
| Application | Tibco | Rendezvous For Z/linux | All | All | All | All |
| Application | Tibco | Rendezvous For Z/os | All | All | All | All |
| Application | Tibco | Rendezvous Network Server | All | All | All | All |
| Application | Tibco | Substation Es | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| TIBCO Rendezvous CVE-2018-12414 Multiple Cross Site Request Forgery Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| TIBCO Security Advisory: November 6, 2018 - TIBCO Rendezvous | TIBCO Software | CONFIRM | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.