"value":"The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0."
"value":"The impact of these vulnerabilities includes the theoretical possibility that a non-administrative user could gain full administrative access to the web interface of the affected component."
"value":"TIBCO has released updated versions of the affected systems which address these issues:\n\nTIBCO MDM versions 9.0.1 and below update to version 9.0.2 or higher.\nTIBCO MDM version 9.1.0 update to version 9.1.2 or higher."