← back
CVE-2019-11211

TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Execution

CVSS 9.9 CRITICALEPSS 3.7%
In short

A vulnerability in TIBCO's R Server component allows an authenticated user to execute malicious code remotely on Linux systems running the containerized TERR service. This could give attackers full control over the affected server.

Technical detail

The server component of TIBCO Enterprise Runtime for R - Server Edition and TIBCO Spotfire Analytics Platform for AWS Marketplace (versions ≤1.2.0 and 10.4.0/10.5.0 respectively) contains an improper input validation flaw in the containerized TERR service on Linux. An authenticated attacker can exploit this to achieve remote code execution with privileges of the container runtime. The vulnerability requires prior authentication and specific deployment configuration (containerized TERR on Linux) to be exploitable.

Summary generated and translated by AI from the official description.
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →