Back

HIGH

TIBCO ActiveMatrix BusinessWorks Fails To Properly Enforce Authentication

Published Apr 9, 2019

Description

The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required. This possibility is restricted to circumstances where HTTP "Basic Authentication" policy is used in conjunction with an XML Authentication resource. The BusinessWorks engine might instead use credentials from a prior HTTP request for authorization purposes. Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 6.4.2.

Affected products

Remediation

Vendor solution

TIBCO has released updated versions of the affected systems which address these issues.

TIBCO ActiveMatrix BusinessWorks versions 6.4.2 and below update to 6.5.0 or higher.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tibco
Published Apr 9, 2019
Updated Sep 16, 2024
Reserved Feb 21, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a