Original release date: March 12, 2024 Last revised: --- Source: TIBCO Software Inc.
Description
The components listed above contain a vulnerability that theoretically allows an Active Spaces client to passively observe data traffic to other clients.
Impact
This impact of this vulnerability includes the theoretical possibility of bypassing table access controls. The attacker cannot actively make queries, but may observe the results of queries by other clients, even though the attacker does not have permission to access that data.
CVSS v3.1 Base Score: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Issue/Introduction
Security Advisory Regarding TIBCO ActiveSpaces Information Leak Vulnerability
Environment
Products Affected
TIBCO ActiveSpaces - Enterprise Edition versions 4.4.0 through 4.9.0
The following components are affected:
* Proxy
* Client
Resolution
TIBCO has released updated versions of the affected systems which address this issue:
TIBCO ActiveSpaces - Enterprise Edition versions 4.4.0 through 4.9.0: update to version 4.9.1 or later