"TITLE":"TIBCO BusinessConnect Trading Community Management Cross-Site Request Forgery Vulnerability"
},
"affects":{
"vendor":{
"vendor_data":[
{
"product":{
"product_data":[
{
"product_name":"TIBCO BusinessConnect Trading Community Management",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_value":"6.1.0"
}
]
}
}
]
},
"vendor_name":"TIBCO Software Inc."
}
]
}
},
"data_format":"MITRE",
"data_type":"CVE",
"data_version":"4.0",
"description":{
"description_data":[
{
"lang":"eng",
"value":"The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below."
"value":"In the worst case, if the victim is a privileged administrator, successful execution of these vulnerabilities can result in an attacker gaining full administrative access to the affected system."
"value":"TIBCO has released updated versions of the affected components which address these issues.\n\nTIBCO BusinessConnect Trading Community Management versions 6.1.0 and below: update to version 6.1.1 or later"
}
],
"source":{
"discovery":"Brett Casper / Wisconsin Physicians Service Insurance Corporation"