TIBCO LogLogic Log Management Intelligence Multiple Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) Vulnerabilities
Published Aug 13, 2019
8.8
HIGHCVSS 3.0
EPSS 0.65%
Description
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as cross-site request forgery (CSRF) attacks. This issue affects: TIBCO Software Inc. TIBCO LogLogic Enterprise Virtual Appliance version 6.2.1 and prior versions. TIBCO Software Inc. TIBCO LogLogic Log Management Intelligence 6.2.1. TIBCO LogLogic LX825 Appliance 0.0.004, TIBCO LogLogic LX1025 Appliance 0.0.004, TIBCO LogLogic LX4025 Appliance 0.0.004, TIBCO LogLogic MX3025 Appliance 0.0.004, TIBCO LogLogic MX4025 Appliance 0.0.004, TIBCO LogLogic ST1025 Appliance 0.0.004, TIBCO LogLogic ST2025-SAN Appliance 0.0.004, and TIBCO LogLogic ST4025 Appliance 0.0.004 using TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below. TIBCO LogLogic LX1035 Appliance 0.0.005, TIBCO LogLogic LX1025R1 Appliance 0.0.004, TIBCO LogLogic LX1025R2 Appliance 0.0.004, TIBCO LogLogic LX4025R1 Appliance 0.0.004, TIBCO LogLogic LX4025R2 Appliance 0.0.004, TIBCO LogLogic LX4035 Appliance 0.0.005, TIBCO LogLogic ST2025-SANR1 Appliance 0.0.004, TIBCO LogLogic ST2025-SANR2 Appliance 0.0.004, TIBCO LogLogic ST2035-SAN Appliance 0.0.005, TIBCO LogLogic ST4025R1 Appliance 0.0.004, TIBCO LogLogic ST4025R2 Appliance 0.0.004, and TIBCO LogLogic ST4035 Appliance 0.0.005 using TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=6.2.1
- Version
-
- Version 6.2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TIBCO Software Inc. | TIBCO LogLogic Enterprise Virtual Appliance | n/a |
| ||||||
| TIBCO Software Inc. | TIBCO LogLogic Log Management Intelligence | n/a |
|
Configuration 1
- ≤ 6.2.1
- ≤ 6.2.1
Configuration 2
- 0.0.004
Running on/with
- n/a
Configuration 3
- 0.0.004
Running on/with
- n/a
Configuration 4
- 0.0.004
Running on/with
- n/a
Configuration 5
- 0.0.004
Running on/with
- n/a
Configuration 6
- 0.0.004
Running on/with
- n/a
Configuration 7
- 0.0.004
Running on/with
- n/a
Configuration 8
- 0.0.004
Running on/with
- n/a
Configuration 9
- 0.0.004
Running on/with
- n/a
Configuration 10
- 0.0.005
Running on/with
- n/a
Configuration 11
- 0.0.004
Running on/with
- n/a
Configuration 12
- 0.0.004
Running on/with
- n/a
Configuration 13
- 0.0.004
Running on/with
- n/a
Configuration 14
- 0.0.004
Running on/with
- n/a
Configuration 15
- 0.0.005
Running on/with
- n/a
Configuration 16
- 0.0.004
Running on/with
- n/a
Configuration 17
- 0.0.004
Running on/with
- n/a
Configuration 18
- 0.0.005
Running on/with
- n/a
Configuration 19
- 0.0.004
Running on/with
- n/a
Configuration 20
- 0.0.004
Running on/with
- n/a
Configuration 21
- 0.0.005
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
TIBCO has released updated versions of the affected systems which address these issues.
TIBCO LogLogic Enterprise Virtual Appliance versions 6.2.1 and below update to version 6.3.0 or higher. TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below update to version 6.3.0 or higher.
Appliances TIBCO LogLogic LX825 Appliance 0.0.004, TIBCO LogLogic LX1025 Appliance 0.0.004, TIBCO LogLogic LX4025 Appliance 0.0.004, TIBCO LogLogic MX3025 Appliance 0.0.004, TIBCO LogLogic MX4025 Appliance 0.0.004, TIBCO LogLogic ST1025 Appliance 0.0.004, TIBCO LogLogic ST2025-SAN Appliance 0.0.004, and TIBCO LogLogic ST4025 Appliance 0.0.004 using TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below update to 6.2.1_02 or higher compatible version (below 6.3.0). Appliances TIBCO LogLogic LX1035 Appliance 0.0.005, TIBCO LogLogic LX1025R1 Appliance 0.0.004, TIBCO LogLogic LX1025R2 Appliance 0.0.004, TIBCO LogLogic LX4025R1 Appliance 0.0.004, TIBCO LogLogic LX4025R2 Appliance 0.0.004, TIBCO LogLogic LX4035 Appliance 0.0.005, TIBCO LogLogic ST2025-SANR1 Appliance 0.0.004, TIBCO LogLogic ST2025-SANR2 Appliance 0.0.004, TIBCO LogLogic ST2035-SAN Appliance 0.0.005, TIBCO LogLogic ST4025R1 Appliance 0.0.004, TIBCO LogLogic ST4025R2 Appliance 0.0.004, and TIBCO LogLogic ST4035 Appliance 0.0.005 using TIBCO LogLogic Log Management Intelligence versions 6.2.1 and below update to 6.3.0 or higher.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.65% (0.00651) | 49.33th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.65% (0.00651) | 49.76th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.05% (0.00050) | 19.91th | v3 (v2023.03.01) |
| Jun 7, 2024 | 0.05% (0.00050) | 19.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00050) | 17.14th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.78% (0.15782) | 92.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.91% (0.02909) | 64.88th | v1 |
| Jan 6, 2022 | 2.91% (0.02909) | 64.55th | v1 |
| Jan 5, 2022 | 0.66% (0.00663) | 48.81th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.66% (0.00663) | 0.00th | v1 |
References (2)
- http://www.tibco.com/services/support/advisories x_refsource_MISCVendor Advisory
- https://www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-13-2019-tibco-loglogic-log-management-intelligence x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.tibco.com/services/support/advisories | x_refsource_MISCVendor Advisory | |
| https://www.tibco.com/support/advisories/2019/08/tibco-security-advisory-august-13-2019-tibco-loglogic-log-management-intelligence | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.