PT-2024-16121 · Tibco · Tibco Operational Intelligence+1

Published

2024-11-12

·

Updated

2024-11-29

·

CVE-2024-10217

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:L/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:X/U:Green
Name of the Vulnerable Software and Affected Versions TIBCO Hawk and TIBCO Operational Intelligence (affected versions not specified)
Description A Cross-Site Scripting (XSS) vulnerability is present in mar.jar and monitoringconsolecommon.jar. This issue allows for potential system manipulation, including the ability to read sensitive files without user interaction, affecting Confidentiality and Integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10217

Affected Products

Tibco Hawk
Tibco Operational Intelligence