PT-2019-12189 · Tibco+1 · Tibco Spotfire Analytics Platform For Aws Marketplace+3
Published
2019-09-18
·
Updated
2020-08-24
·
CVE-2019-11211
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below
TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0; 10.5.0
Description
The issue theoretically allows an authenticated user to trigger remote code execution in certain circumstances. When the affected component runs with the containerized TERR service on Linux, the host can theoretically be tricked into running malicious code.
Recommendations
For TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, update to a version above 1.2.0 to resolve the issue.
For TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0; 10.5.0, consider restricting access to the TERR service on Linux until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux
Terr
Tibco Enterprise Runtime For R - Server Edition
Tibco Spotfire Analytics Platform For Aws Marketplace