CVE-2022-30570
TIBCO Data Virtualization Access Control Vulnerability
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
19 jul 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for AWS Marketplace contains an easily exploitable vulnerability that allows a low privileged attacker with network access to obtain read access to application information on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 8.5.2 and below and TIBCO Data Virtualization for AWS Marketplace: versions 8.5.2 and below.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
TIBCO Software Inc. · TIBCO Data VirtualizationTIBCO Software Inc. · TIBCO Data Virtualization for AWS Marketplace¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →