PT-2019-12188 · Tibco · Tibco Spotfire Analytics Platform For Aws Marketplace+1
Publicado
2019-09-18
·
Atualizado
2020-08-24
·
CVE-2019-11210
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below
TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0
Description
The issue allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component.
Recommendations
For TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, update to a version above 1.2.0 to resolve the issue.
For TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0, consider restricting access to the server component until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tibco Enterprise Runtime For R - Server Edition
Tibco Spotfire Analytics Platform For Aws Marketplace