Security Advisory regarding TIBCO Active Matrix Service Grid Administrator Remote Code Execution

Security Advisory regarding TIBCO Active Matrix Service Grid Administrator Remote Code Execution

book

Article ID: KB0108074

calendar_today

Updated On:

Products Versions
TIBCO BPM Enterprise (formerly TIBCO ActiveMatrix BPM) 4.2.0 and below
TIBCO ActiveMatrix Policy Director 1.1.0 and below
TIBCO ActiveMatrix Service Bus 3.3.0 and below

Description

TIBCO Active Matrix Service Grid Administrator Remote Code Execution

  Original release date: April 24, 2019
  Last revised: --
  Source: TIBCO Software Inc.

Description

  The component listed above contains a vulnerability wherein a user without
  privileges to upload distributed application archives ("Upload DAA"
  permission) can theoretically upload arbitrary code, and in some
  circumstances then execute that code on ActiveMatrix Service Grid nodes.


Impact

  The impact of this vulnerability includes the theoretical possibility that
  a user without privileges to upload code could execute arbitrary code on
  ActiveMatrix Service Grid nodes.

  CVSS v3 Base Score: 9.9 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
 

Environment

Systems Affected TIBCO ActiveMatrix BPM versions 4.2.0 and below TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric versions 4.2.0 and below TIBCO ActiveMatrix Policy Director versions 1.1.0 and below TIBCO ActiveMatrix Service Bus versions 3.3.0 and below TIBCO ActiveMatrix Service Grid versions 3.3.1 and below TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric versions 3.3.0 and below TIBCO Silver Fabric Enabler for ActiveMatrix BPM versions 1.4.1 and below TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid versions 1.3.1 and below The following component is affected: * administrative server

Resolution

Solution

  TIBCO has released updated versions of the affected components which address
  these issues.

  For each affected system, update to the corresponding software versions:

  TIBCO ActiveMatrix BPM versions 4.2.0 and below update to version 4.3.0
    or higher

  TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric versions 4.2.0
    and below update to 4.3.0 or higher

  TIBCO ActiveMatrix Policy Director versions 1.1.0 and below update to
    version 2.0.0 or higher. Due to the scheduled retirement of this product
    in early 2021, customers are strongly encouraged to contact TIBCO Support
    in order to explore alternative paths for remediation.

  TIBCO ActiveMatrix Service Bus versions 3.3.0 and below update to
    TIBCO ActiveMatrix Service Grid version 3.4.0 or higher (product
    functionality has been consolidated)

  TIBCO ActiveMatrix Service Grid versions 3.3.1 and below update to version
    3.4.0 or higher

  TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric versions
    3.3.0 and below update to version 3.4.0 or higher

  TIBCO Silver Fabric Enabler for ActiveMatrix BPM versions 1.4.1 and below
    update to version 1.4.2 or higher

  TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid versions 1.3.1 and
    below update to version 1.3.2 or higher
 

Issue/Introduction

SG0419-2

Additional Information

  http://www.tibco.com/services/support/advisories
  CVE-2019-8992