PT-2019-19290 · Tibco · Tibco Data Science For Aws+1
CVE-2019-8987
·
Publicado
2019-03-26
·
Atualizado
2022-10-14
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
TIBCO Data Science for AWS versions up to and including 6.4.0
TIBCO Spotfire Data Science versions up to and including 6.4.0
Description
The application server component contains a persistent cross-site scripting issue that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users.
Recommendations
For TIBCO Data Science for AWS versions up to and including 6.4.0, update to a version later than 6.4.0 to resolve the issue.
For TIBCO Spotfire Data Science versions up to and including 6.4.0, update to a version later than 6.4.0 to resolve the issue.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tibco Data Science For Aws
Tibco Spotfire Data Science