Impact
An authenticated user can submit malicious data via the Tibco Administrator web console that the application fails to validate properly, creating an input injection flaw. This vulnerability may allow the attacker to alter system configuration, inject commands, or otherwise compromise the integrity of the administration environment. Because the flaw requires elevated privilege within the console, the attack vectors are limited to authenticated sessions, but the impact on confidentiality, integrity, and availability of the platform remains significant.
Affected Systems
Tibco Administrator versions 5.13.0 and earlier are affected. The advisory lists no additional versions, indicating that all builds prior to the published fix are vulnerable. Deployments that host the web‑based console, especially those exposed to external networks or integrated with other services, are therefore at risk.
Risk and Exploitability
The CVSS score of 8.7 places this flaw in the High severity range. Exploitation requires valid credentials, so attackers must either compromise a user account or obtain credentials by social engineering. The EPSS score is not available, but the lack of publicly reported exploits and the absence of a CISA KEV listing suggest that the present exploitation risk may be moderate. Nonetheless, the high severity combined with the authenticated nature warrants prompt remediation.
OpenCVE Enrichment