Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11210

Опубликовано: 18 сент. 2019
Источник: nvd
CVSS3: 10
CVSS3: 10
CVSS2: 10
EPSS Низкий

Описание

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tibco:enterprise_runtime_for_r:*:*:*:*:server:*:*:*
Версия до 1.2.0 (включая)
cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:10.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tibco:spotfire_analytics_platform_for_aws:10.5.0:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02816
Низкий

10 Critical

CVSS3

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analytics Platform for AWS Marketplace contains a vulnerability that theoretically allows an unauthenticated user to bypass access controls and remotely execute code using the operating system account hosting the affected component. This issue affects: TIBCO Enterprise Runtime for R - Server Edition versions 1.2.0 and below, and TIBCO Spotfire Analytics Platform for AWS Marketplace versions 10.4.0 and 10.5.0.

EPSS

Процентиль: 86%
0.02816
Низкий

10 Critical

CVSS3

10 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo