CVE-2019-8994
Summary
| CVE | CVE-2019-8994 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-24 21:29:00 UTC |
| Updated | 2021-11-06 03:39:00 UTC |
| Description | The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contains vulnerabilities where an authenticated user can change settings that can theoretically adversely impact other users. Affected releases are TIBCO Software Inc.'s TIBCO ActiveMatrix BPM: versions up to and including 4.2.0, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric: versions up to and including 4.2.0, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM: versions up to and including 1.4.1. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tibco | Activematrix Business Process Management | All | All | All | All |
| Application | Tibco | Activematrix Business Process Management | All | All | All | All |
| Application | Tibco | Activematrix Business Process Mangement | All | All | All | All |
| Application | Tibco | Activematrix Business Process Mangement | All | All | All | All |
| Application | Tibco | Silver Fabric Enabler | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisory | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| TIBCO Security Advisory: April 24, 2019 - TIBCO ActiveMatrix BPM - 2019-8994 | TIBCO Software | MISC | www.tibco.com | Vendor Advisory |
| Multiple TIBCO ActiveMatrix BPM Products CVE-2019-8994 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.