Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2018-4382 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages, and may disclose the contents of files accessible to a running BusinessWorks engine Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks for z/Linux: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric: versions up to and including 5.13.0. |
Solution
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO ActiveMatrix BusinessWorks versions 5.13.0 and below update to version 5.13.1 or higher, TIBCO ActiveMatrix BusinessWorks for z/Linux versions 5.13.0 and below update to version 5.13.1 or higher, TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric versions 5.13.0 and below update to version 5.13.1 or higher.
Workaround
No workaround given by the vendor.
No history.

Status: PUBLISHED
Assigner: tibco
Published:
Updated: 2024-09-17T02:56:30.441Z
Reserved: 2018-06-14T00:00:00
Link: CVE-2018-12408

No data.

Status : Modified
Published: 2018-08-08T14:29:00.317
Modified: 2024-11-21T03:45:09.877
Link: CVE-2018-12408

No data.

No data.