CVE-2019-11209

Severity

65%

Complexity

80%

Confidentiality

106%

The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIBCO FTL Enterprise Edition contains a vulnerability that theoretically fails to properly enforce access controls. This issue affects TIBCO FTL Community Edition 6.0.0; 6.0.1; 6.1.0, TIBCO FTL Developer Edition 6.0.1; 6.1.0, and TIBCO FTL Enterprise Edition 6.0.0; 6.0.1; 6.1.0.

The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIBCO FTL Enterprise Edition contains a vulnerability that theoretically fails to properly enforce access controls. This issue affects TIBCO FTL Community Edition 6.0.0; 6.0.1; 6.1.0, TIBCO FTL Developer Edition 6.0.1; 6.1.0, and TIBCO FTL Enterprise Edition 6.0.0; 6.0.1; 6.1.0.

CVSS 3.0 Base Score 8.8. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 6.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:P).

Overview

Type

TIBCO FTL

First reported 5 years ago

2019-08-20 18:15:00

Last updated 5 years ago

2019-10-09 23:45:00

Affected Software

TIBCO FTL 6.0.0 Community Edition

6.0.0

TIBCO FTL 6.0.0 Enterprise Edition

6.0.0

TIBCO FTL 6.0.1 Community Edition

6.0.1

TIBCO FTL 6.0.1 Developer Edition

6.0.1

TIBCO FTL 6.0.1 Enterprise Edition

6.0.1

TIBCO FTL 6.1.0 Community Edition

6.1.0

TIBCO FTL 6.1.0 Developer Edition

6.1.0

TIBCO FTL 6.1.0 Enterprise Edition

6.1.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.