TIBCO Omni-Gen Hotfixes to Remediate CVE-2022-29464

TIBCO Omni-Gen Hotfixes to Remediate CVE-2022-29464

book

Article ID: KB0072340

calendar_today

Updated On:

Products Versions
ibi Omni 3.x and 4.x releases
ibi Omni-Gen MDM 3.x and 4.x releases
TIBCO Omni-Gen DQ Server 3.x and 4.x releases

Description

TIBCO is aware of the recently announced WSO2 vulnerability (CVE-2022-29464).  This vulnerability potentially allows unrestricted file upload with resultant remote code execution.

Issue/Introduction

These hotfixes address CVE-2022-29464, the remote code execution vulnerability in WSO2.

Environment

These hotfixes apply to the TIBCO Omni-Gen product suite for the versions listed on all supported platforms.

Resolution

These hotfixes can be downloaded from the TIBCO Support Customer Portal Web User Interface, using your username and password for the TIBCO Support Web.

Once logged in, select Hotfixes from the Downloads menu. Navigate to the hotfix location: AvailableDownloads/ibi. Then select the applicable product(s) and release(s):
  • For 3.x releases, navigate to 3.16 and select HF-007.
  • For 4.1 releases, navigate to 4.1 and select HF-004.

Additional Information

CVE-2022-29464
WSO2 Advisory

Attachments

TIBCO Omni-Gen Hotfixes to Remediate CVE-2022-29464 get_app
TIBCO Omni-Gen Hotfixes to Remediate CVE-2022-29464 get_app