CVE-2018-12416
TIBCO DataSynapse GridServer Manager Component Vulnerable to Cross-Site Request Forgery
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 Nov 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The GridServer Broker and GridServer Director components of TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an unauthenticated user to perform cross-site request forgery (CSRF). Affected releases are TIBCO Software Inc. TIBCO DataSynapse GridServer Manager: versions up to and including 5.2.0; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; 6.2.0; 6.3.0.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
Affected products
TIBCO Software Inc. · TIBCO DataSynapse GridServer ManagerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →