CVE-2019-11212 MEDIUM

CVE-2019-11212: TIBCO MDM Exposes Cross-Site Scripting Vulnerabilities

Vendor Tibco Software Inc.
Product TIBCO MDM
Published October 9, 2019
Last update September 16, 2024

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.

Key dates

02Disclosure timeline

October 9, 2019 CVE published
September 16, 2024 Record updated