← volver
CVE-2019-11211critical

TIBCO Enterprise Runtime for R Server Running On Linux With Containerized TERR Service Vulnerable To Remote Code Execution

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.9epss 3.7%
probabilidad de explotación
3.7%top 11% de las CVE
explotación observada
noninguna fuente lo reporta
En resumen

Una vulnerabilidad en el componente TIBCO R Server permite que un usuario autenticado ejecute código malicioso remotamente en sistemas Linux con el servicio TERR en contenedor. Esto podría dar a los atacantes control total del servidor afectado.

Detalle técnico

El componente servidor de TIBCO Enterprise Runtime for R - Server Edition y TIBCO Spotfire Analytics Platform for AWS Marketplace (versiones ≤1.2.0 y 10.4.0/10.5.0) contiene una falla de validación de entrada en el servicio TERR en contenedor en Linux. Un atacante autenticado puede explotar esto para lograr ejecución remota de código con privilegios del runtime del contenedor. La vulnerabilidad requiere autenticación previa y configuración de implementación específica (TERR en contenedor en Linux) para ser explotable.

Resumen generado y traducido por IA a partir de la descripción oficial.
The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux the host can theoretically be tricked into running malicious code. This issue affects: TIBCO Enterprise Runtime for R - Server Edition version 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace 10.4.0; 10.5.0.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H