René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

140 lines
4.7 KiB
JSON

{
"id": "CVE-2019-8987",
"sourceIdentifier": "security@tibco.com",
"published": "2019-03-26T18:29:01.170",
"lastModified": "2022-10-14T09:31:36.053",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0."
},
{
"lang": "es",
"value": "El componente del servidor de la aplicaci\u00f3n de TIBCO Data Science for AWS y TIBCO Spotfire Data Science, de TIBCO Software Inc., contiene una vulnerabilidad de Cross-Site Scripting (XSS) persistente que, en teor\u00eda, permite que un usuario autenticado obtenga acceso a todas las funcionalidades de la interfaz web disponibles para los usuarios con m\u00e1s privilegios. Las versiones afectadas de los productos de TIBCO Software Inc. son TIBCO Data Science for AWS: versiones hasta e incluyendo la 6.4.0 y TIBCO Spotfire Data Science: versiones hasta e incluyendo la 6.4.0."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
],
"cvssMetricV30": [
{
"source": "security@tibco.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "LOW",
"baseScore": 7.6,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.1,
"impactScore": 5.5
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 3.5
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.8,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:data_science_for_aws:*:*:*:*:*:*:*:*",
"versionEndIncluding": "6.4.0",
"matchCriteriaId": "45BF0A38-3E92-4010-A57A-6A7FF6B1DCEE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tibco:spotfire_data_science:*:*:*:*:*:*:*:*",
"versionEndIncluding": "6.4.0",
"matchCriteriaId": "98088672-D302-438E-9898-E877853B7E1C"
}
]
}
]
}
],
"references": [
{
"url": "http://www.tibco.com/services/support/advisories",
"source": "security@tibco.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.tibco.com/support/advisories/2019/03/tibco-security-advisory-march-26-2019-tibco-spotfire-data-science-2019-8987",
"source": "security@tibco.com",
"tags": [
"Vendor Advisory"
]
}
]
}