Security Advisory Regarding TIBCO ActiveSpaces

Security Advisory Regarding TIBCO ActiveSpaces

book

Article ID: KB0107931

calendar_today

Updated On:

Products Versions
TIBCO ActiveSpaces 4.4.0 through 4.9.0

Description

IBCO ActiveSpaces Information Leak Vulnerability

  Original release date: March 12, 2024
  Last revised: ---
  Source: TIBCO Software Inc.

Description

  The components listed above contain a vulnerability that theoretically allows
  an Active Spaces client to passively observe data traffic to other clients.


Impact

  This impact of this vulnerability includes the theoretical possibility of
  bypassing table access controls.  The attacker cannot actively make queries,
  but may observe the results of queries by other clients, even though the
  attacker does not have permission to access that data.

  CVSS v3.1 Base Score: 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

Issue/Introduction

Security Advisory Regarding TIBCO ActiveSpaces Information Leak Vulnerability

Environment

Products Affected TIBCO ActiveSpaces - Enterprise Edition versions 4.4.0 through 4.9.0 The following components are affected: * Proxy * Client

Resolution

  TIBCO has released updated versions of the affected systems which address this
  issue:

  TIBCO ActiveSpaces - Enterprise Edition versions 4.4.0 through 4.9.0: update
    to version 4.9.1 or later
 

Additional Information

  https://community.tibco.com/advisories
  CVE-2024-1137