Back

HIGH

TIBCO ActiveMatrix BusinessWorks 5.X XML eXternal Entity Vulnerability

Published Aug 8, 2018

Description

The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages, and may disclose the contents of files accessible to a running BusinessWorks engine Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks for z/Linux: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric: versions up to and including 5.13.0.

Affected products

Remediation

Vendor solution

TIBCO has released updated versions of the affected components which address these issues. For each affected system, update to the corresponding software versions:

TIBCO ActiveMatrix BusinessWorks versions 5.13.0 and below update to version 5.13.1 or higher, TIBCO ActiveMatrix BusinessWorks for z/Linux versions 5.13.0 and below update to version 5.13.1 or higher, TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric versions 5.13.0 and below update to version 5.13.1 or higher.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tibco
Published Aug 8, 2018
Updated Sep 17, 2024
Reserved Jun 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a