The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-19670 The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.
Fixes

Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO iProcess Workspace (Browser) versions 11.6.0 and below update to version 11.8.0 or higher


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-17T04:08:46.251Z

Reserved: 2020-10-14T00:00:00

Link: CVE-2020-27146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-10T18:15:11.900

Modified: 2024-11-21T05:20:46.660

Link: CVE-2020-27146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.