Description
The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.
Published: 2021-01-12
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

TIBCO has released updated versions of the affected components which address these issues. TIBCO EBX Add-ons versions 4.4.2 and below update to version 4.4.3 or higher

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-19672 The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO EBX Add-ons contain a vulnerability that theoretically allows a low privileged attacker with network access to execute an XML External Entity (XXE) attack. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.4.2 and below.
History

No history.

Subscriptions

Tibco Ebx Add-ons
cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2024-09-16T16:22:54.482Z

Reserved: 2020-10-14T00:00:00.000Z

Link: CVE-2020-27148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-12T18:15:13.033

Modified: 2024-11-21T05:20:46.873

Link: CVE-2020-27148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses