Security Advisory Regarding TIBCO EBX

Security Advisory Regarding TIBCO EBX

book

Article ID: KB0108029

calendar_today

Updated On:

Products Versions
TIBCO EBX 4.4.2 and below

Description

TIBCO EBX EXML External Entity

  Original release date: January 12, 2021
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The components listed above contain a vulnerability that theoretically allows
  a low privileged attacker with network access to execute an XML External
  Entity (XXE) attack.

Impact

  The impact of these vulnerabilities include the possibility that an attacker
  would gain unauthorized read access to TIBCO EBX data, and the ability to
  cause a partial denial of service (partial DOS) on the affected system.

  CVSS v3 Base Score: 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L)

Issue/Introduction

Security Advisory Regarding TIBCO EBX EXML External Entity

Environment

Systems Affected TIBCO EBX Add-ons versions 4.4.2 and below The following components are affected: * TIBCO EBX Add-on for Oracle Hyperion EPM * TIBCO EBX Data Exchange Add-on * TIBCO EBX Insight Add-on

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO EBX Add-ons versions 4.4.2 and below update to version 4.4.3 or higher
 

Additional Information

http://www.tibco.com/services/support/advisories
CVE-2020-27148