TIBCO Active Matrix Service Grid CVE-2019-8991 Multiple Security Vulnerabilities
BID:108059
CVE-2019-8991 |Info
TIBCO Active Matrix Service Grid CVE-2019-8991 Multiple Security Vulnerabilities
| Bugtraq ID: | 108059 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-8991 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2019 12:00AM |
| Updated: | Apr 24 2019 12:00AM |
| Credit: | Giulio Comi and Flavio Baldassi of Horizon Security. |
| Vulnerable: |
TIBCO Silver Fabric for ActiveMatrix Service Grid Distribution 3.3 TIBCO Silver Fabric for ActiveMatrix BPM Distribution 4.2 TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid 1.3.1 TIBCO Silver Fabric Enabler for ActiveMatrix BPM 1.4.1 TIBCO Silver Fabric Enabler for ActiveMatrix BPM 1.4 TIBCO ActiveMatrix Service Grid 3.3.1 TIBCO ActiveMatrix Service Grid 3.1.5 TIBCO ActiveMatrix Service Grid 3.1.1 TIBCO ActiveMatrix Service Grid 3.1 TIBCO ActiveMatrix Service Grid 3.0.2 TIBCO ActiveMatrix Service Grid 3.0.1 TIBCO ActiveMatrix Service Grid 3.0 TIBCO ActiveMatrix Service Grid 2.3.2 TIBCO ActiveMatrix Service Grid 2.3.1 TIBCO ActiveMatrix Service Bus 3.3 TIBCO ActiveMatrix Service Bus 3.1.5 TIBCO ActiveMatrix Service Bus 3.0.2 TIBCO ActiveMatrix Service Bus 3.0.1 TIBCO ActiveMatrix Service Bus 3.0 TIBCO ActiveMatrix Service Bus 2.3.2 TIBCO ActiveMatrix Service Bus 2.3.1 TIBCO ActiveMatrix Policy Director 1.1 TIBCO ActiveMatrix BPM 4.2 TIBCO ActiveMatrix BPM 1.3 TIBCO ActiveMatrix BPM 1.0.3 TIBCO ActiveMatrix BPM 1.0.2 |
| Not Vulnerable: |
TIBCO Silver Fabric for ActiveMatrix Service Grid Distribution 3.4 TIBCO Silver Fabric for ActiveMatrix BPM Distribution 4.3 TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid 1.3.2 TIBCO Silver Fabric Enabler for ActiveMatrix BPM 1.4.2 TIBCO ActiveMatrix Service Grid 3.4 TIBCO ActiveMatrix Service Bus 3.4 TIBCO ActiveMatrix Policy Director 2.0 TIBCO ActiveMatrix BPM 4.3 |
Discussion
TIBCO Active Matrix Service Grid CVE-2019-8991 Multiple Security Vulnerabilities
TIBCO Active Matrix Service Grid is prone to multiple cross-site scripting vulnerabilities and multiple cross-site request-forgery vulnerabilities.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials or perform unauthorized actions. Other attacks may also be possible.
The following TIBCO ActiveMatrix BPM versions are vulnerable:
TIBCO ActiveMatrix BPM version 4.2.0 and prior are vulnerable
TIBCO Silver Fabric for ActiveMatrix BPM Distribution version 4.2.0 and prior are vulnerable
TIBCO ActiveMatrix Policy Director version 1.1.0 and prior are vulnerable
TIBCO ActiveMatrix Service Bus version 3.3.0 and prior are vulnerable
TIBCO ActiveMatrix Service Grid version 3.3.1 and prior are vulnerable
TIBCO Silver Fabric for ActiveMatrix Service Grid Distribution version 3.3.0 and prior are vulnerable
TIBCO Silver Fabric Enabler for ActiveMatrix BPM version 1.4.1 and prior are vulnerable
TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid version 1.3.1 and prior are vulnerable
TIBCO Active Matrix Service Grid is prone to multiple cross-site scripting vulnerabilities and multiple cross-site request-forgery vulnerabilities.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials or perform unauthorized actions. Other attacks may also be possible.
The following TIBCO ActiveMatrix BPM versions are vulnerable:
TIBCO ActiveMatrix BPM version 4.2.0 and prior are vulnerable
TIBCO Silver Fabric for ActiveMatrix BPM Distribution version 4.2.0 and prior are vulnerable
TIBCO ActiveMatrix Policy Director version 1.1.0 and prior are vulnerable
TIBCO ActiveMatrix Service Bus version 3.3.0 and prior are vulnerable
TIBCO ActiveMatrix Service Grid version 3.3.1 and prior are vulnerable
TIBCO Silver Fabric for ActiveMatrix Service Grid Distribution version 3.3.0 and prior are vulnerable
TIBCO Silver Fabric Enabler for ActiveMatrix BPM version 1.4.1 and prior are vulnerable
TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid version 1.3.1 and prior are vulnerable
Exploit / POC
TIBCO Active Matrix Service Grid CVE-2019-8991 Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].