TIBCO Administrator - Enterprise Edition For zLinux
5.11.1 and below, 5.10.2 and below
Description
TIBCO Administrator CSV injection vulnerability
Original release date: April 20, 2021 Last revised: --- Source: TIBCO Software Inc.
Description
The component listed above contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a persistent CSV injection attack from the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker.
Impact
Successful execution of this vulnerability provides the attacker with the ability to exploit the inherent trust an end-user has in the affected system and may allow an attacker to:- Infect end users with viruses or malware- Gain control over an end-user's computer and execute operating system commands- Steal sensitive information- Forge, spoof or modify data that appears to be generated by the affected system.
CVSS v3 Base Score: 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L)