CVE-2018-12411
TIBCO ActiveSpaces Administrative Daemon Vulnerable to CSRF Attacks
The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: 3.3.0; 3.4.0; 3.5.0, TIBCO ActiveSpaces - Developer Edition: 3.0.0; 3.1.0; 3.3.0; 3.4.0; 3.5.0, and TIBCO ActiveSpaces - Enterprise Edition: 3.0.0; 3.1.0; 3.2.0; 3.3.0; 3.4.0; 3.5.0.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
TIBCO Software Inc. · TIBCO ActiveSpaces - Community EditionTIBCO Software Inc. · TIBCO ActiveSpaces - Developer EditionTIBCO Software Inc. · TIBCO ActiveSpaces - Enterprise EditionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →