CVE-2019-8991
Summary
| CVE | CVE-2019-8991 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-24 21:29:00 UTC |
| Updated | 2022-10-14 09:30:00 UTC |
| Description | The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid contains multiple vulnerabilities that may allow for cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up to and including 4.2.0, TIBCO ActiveMatrix Policy Director: versions up to and including 1.1.0, TIBCO ActiveMatrix Service Bus: versions up to and including 3.3.0, TIBCO ActiveMatrix Service Grid: versions up to and including 3.3.1, TIBCO Silver Fabric Enabler for ActiveMatrix BPM: versions up to and including 1.4.1, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid: versions up to and including 1.3.1. |
Risk And Classification
Problem Types: CWE-352 | CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Activematrix Bpm | All | All | All | All |
| Application | Tibco | Activematrix Bpm | All | All | All | All |
| Application | Tibco | Activematrix Policy Director | All | All | All | All |
| Application | Tibco | Activematrix Service Bus | All | All | All | All |
| Application | Tibco | Activematrix Service Grid | All | All | All | All |
| Application | Tibco | Activematrix Service Grid | All | All | All | All |
| Application | Tibco | Silver Fabric Enabler | All | All | All | All |
| Application | Tibco | Silver Fabric Enabler | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| TIBCO Active Matrix Service Grid CVE-2019-8991 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| TIBCO Security Advisory: April 24, 2019 - TIBCO Active Matrix Service Grid - 2019-8991 | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: TIBCO would like to extend its appreciation to Giulio Comi and Flavio Baldassi of Horizon Security for discovery of these vulnerabilities.
There are currently no legacy QID mappings associated with this CVE.