CVE-2019-11203
Summary
| CVE | CVE-2019-11203 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-24 21:29:00 UTC |
| Updated | 2021-11-06 03:38:00 UTC |
| Description | The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain cross site scripting (XSS) and cross-site request forgery vulnerabilities. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up to and including 4.2.0, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM: versions up to and including 1.4.1. |
Risk And Classification
Problem Types: CWE-352 | CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Activematrix Business Process Management | All | All | All | All |
| Application | Tibco | Activematrix Business Process Management | All | All | All | All |
| Application | Tibco | Activematrix Business Process Management | All | All | All | All |
| Application | Tibco | Silver Fabric Enabler | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| TIBCO Security Advisory: April 24, 2019 - TIBCO ActiveMatrix BPM - 2019-11203 | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: TIBCO would like to extend its appreciation to Giulio Comi and Flavio Baldassi of Horizon Security for discovery of these vulnerabilities.
There are currently no legacy QID mappings associated with this CVE.