TIBCO takes its security responsibilities very seriously. This page provides information about TIBCO security and how customers or security researchers can contact TIBCO to report or ask about a security issue.
TIBCO takes its security responsibilities very seriously. This page provides information about TIBCO security and how customers or security researchers can contact TIBCO to report or ask about a security issue.
The TIBCO continues to work on investigating and identifying mitigations for the Meltdown (CVE-2017-5754) and Spectre (CVE-2017-5753 and CVE-2017-5715) vulnerabilities. The table below contains the current status of these efforts organized by TIBCO delivery and deployment options.
TIBCO Offering | Mitigation status |
---|---|
Customer deployed TIBCO software Other software running on the same operating system as TIBCO software could potentially be vulnerable and gain access to information held by processes running TIBCO software. |
No patches to TIBCO software are required to address these vulnerabilities. TIBCO recommends that customers consult with their operating systems (OS) vendors for patching recommendations and guidance on the impact on performance. Links to commonly used OS vendor guidance can be found at the bottom of the first update. |
Virtual machine images provided by TIBCO |
TIBCO is working on updates to the virtual images it provides. TIBCO will update customers by January 31, 2018 with the release date for images that address these vulnerabilities. |
Hardware appliances - resolved |
The following TIBCO appliances are not vulnerable and do not require any action by the customer.
|
Hardware appliances - pending |
TIBCO is working on remediations for the following appliances. TIBCO will update customers by January 31, 2018 with the release date for appliance remediations that address these vulnerabilities.
|
TIBCO-hosted services |
TIBCO is updating its hosted services to address these vulnerabilities and will have completed updates to all hosted services, with the exception of TIBCO Reward and TIBCO Mashery, by January 29, 2018. An update on TIBCO Reward and TIBCO Mashery hosted services will be provided by January 31, 2018. |
Web-browser clients of TIBCO software |
TIBCO recommends customers update their web browsers. Links to specific browser vendor guidance can be found at the bottom of the first update. Some browsers can also be configured with site isolation. Consult your browser documentation for more details. |
Discover the people, philosophy, and practices behind TIBCO
Find helpful links, documentation, and tech support
Collaborate and share knowledge with other TIBCO users
Stay up to speed on what’s new with TIBCO
Browse our comprehensive resource library
Read the latest trends, ideas, and product news from TIBCO
Don’t miss out on upcoming conferences, webinars, and more
Explore think-pieces geared towards executive leaders
Pursue your passion in an award-winning workplace
Up-to-date security release information
Get in touch with us and learn more about TIBCO
A global leader in enterprise data, TIBCO empowers its customers to connect, unify, and confidently predict business outcomes, solving the world’s most complex data-driven challenges.