CVE-2017-5536
TIBCO DataSynapse GridServer manager component vulnerable to cross-site scripting attacks
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.3EPSS 0.7%KEV nãoPoC —Patch —
Ciclo de vida
01 mai 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Produtos afetados
TIBCO Software Inc. · TIBCO DataSynapse GridServer ManagerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →