Known Vulnerabilities for Nimbus by Tibco
Listed below are 4 of the newest known vulnerabilities associated with "Nimbus" by "Tibco".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-84179 json | Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82441 json | Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which th... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82437 json | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemo... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82434 json | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` ... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82433 json | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorizati... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82432 json | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance ope... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82431 json | Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, bef... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82427 json | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor l... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-82426 json | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-si... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2023-26218 json | The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XS... | 9 - CRITICAL | 2023-09-29 | 2023-10-04 |