The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-19672 | The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below. |
Fixes
Solution
TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX Add-ons versions 4.4.2 and below update to version 4.4.3 or higher
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tibco
Published:
Updated: 2024-09-16T16:22:54.482Z
Reserved: 2020-10-14T00:00:00
Link: CVE-2020-27148
No data.
Status : Modified
Published: 2021-01-12T18:15:13.033
Modified: 2024-11-21T05:20:46.873
Link: CVE-2020-27148
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD