Back

MEDIUM

TIBCO MDM Exposes Cross-Site Scripting Vulnerabilities

Published Oct 9, 2019

Description

The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.

Affected products

Remediation

Vendor solution

TIBCO has released updated versions of the affected systems which address these issues:

TIBCO MDM versions 9.0.1 and below update to version 9.0.2 or higher. TIBCO MDM version 9.1.0 update to version 9.1.2 or higher.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tibco
Published Oct 9, 2019
Updated Sep 16, 2024
Reserved Apr 12, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a