The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2018-17204 | The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1. |
Fixes
Solution
TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions: TIBCO Runtime Agent versions 5.10.0 and below update to version 5.10.1 or higher TIBCO Runtime Agent for z/Linux versions 5.9.1 and below update to version 5.10.1 or higher
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: tibco
Published:
Updated: 2024-09-16T20:31:50.987Z
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5434

No data.

Status : Modified
Published: 2018-06-13T13:29:00.517
Modified: 2024-11-21T04:08:47.693
Link: CVE-2018-5434

No data.

No data.