TIBCO Security Advisory: October 8, 2019 - TIBCO MDM
- TIBCO MDM versions 9.0.1 and below
- TIBCO MDM version 9.1.0
The following component is affected:
- MDM server
The component listed above contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks.
The impact of these vulnerabilities includes the theoretical possibility that a non-administrative user could gain full administrative access to the web interface of the affected component.
CVSS v3 Base Score: 6.3 (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N)
TIBCO has released updated versions of the affected systems which address these issues:
- TIBCO MDM versions 9.0.1 and below update to version 9.0.2 or higher
- TIBCO MDM version 9.1.0 update to version 9.1.2 or higher