TIBCO takes its security responsibilities very seriously. This page provides information about TIBCO security and how customers or security researchers can contact TIBCO to report or ask about a security issue.
TIBCO takes its security responsibilities very seriously. This page provides information about TIBCO security and how customers or security researchers can contact TIBCO to report or ask about a security issue.
The TIBCO Security team is aware of the recently announced Java Spring Framework vulnerabilities (CVE-2022-22963, CVE-2022-22965), with one of them being referred to as “Spring4Shell”. These vulnerabilities potentially enable an attacker to execute arbitrary code by taking advantage of poor data bindings and/or malicious expression language statements.
TIBCO is also aware of CVE-2022-22950, and this issue is under investigation as part of our response to CVE-2022-22963 and CVE-2022-22965.
TIBCO’s Security team is actively monitoring the still evolving situation and updates with regards to the Java Spring Framework and our Product Security Incident Response Team (PSIRT) is actively evaluating how this vulnerability may affect TIBCO products and cloud services.
We will provide updates as more information becomes available and we complete our investigation. This information will include which TIBCO products and services are affected and how customers and users of those products and services can best mitigate or protect themselves from being exploited by this vulnerability.
For more information on the vulnerability, please see the following references:
CVE-2022-22950 (https://tanzu.vmware.com/security/cve-2022-22950)
CVE-2022-22963 (https://tanzu.vmware.com/security/cve-2022-22963)
CVE-2022-22965 (https://tanzu.vmware.com/security/cve-2022-22965)
Discover the people, philosophy, and practices behind TIBCO
Find helpful links, documentation, and tech support
Collaborate and share knowledge with other TIBCO users
Stay up to speed on what’s new with TIBCO
Browse our comprehensive resource library
Read the latest trends, ideas, and product news from TIBCO
Don’t miss out on upcoming conferences, webinars, and more
Pursue your passion in an award-winning workplace
Up-to-date security release information
Get in touch with us and learn more about TIBCO
A global leader in enterprise data, TIBCO empowers its customers to connect, unify, and confidently predict business outcomes, solving the world’s most complex data-driven challenges.