PT-2019-19290 · Tibco · Tibco Data Science For Aws+1

CVE-2019-8987

·

Publicado

2019-03-26

·

Atualizado

2022-10-14

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions TIBCO Data Science for AWS versions up to and including 6.4.0 TIBCO Spotfire Data Science versions up to and including 6.4.0
Description The application server component contains a persistent cross-site scripting issue that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users.
Recommendations For TIBCO Data Science for AWS versions up to and including 6.4.0, update to a version later than 6.4.0 to resolve the issue. For TIBCO Spotfire Data Science versions up to and including 6.4.0, update to a version later than 6.4.0 to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8987

Produtos afetados

Tibco Data Science For Aws
Tibco Spotfire Data Science